XWorm is a Windows-focused malware family and commodity remote-access trojan used in criminal intrusion campaigns. It is commonly delivered through staged infection chains and malware-as-a-service ecosystems, including loader-based delivery such as PhantomVAI, and has also appeared in trojanized builder variants. Observed delivery methods include ClickFix-style social-engineering lures that abuse PowerShell and mshta.exe to retrieve intermediate payloads, followed by process injection or hollowing into trusted Windows processes. XWorm-associated activity has used dynamic DNS infrastructure extensively and has been linked to rapidly rotated command-and-control infrastructure. Reported tradecraft includes DLL side-loading, execution within trusted process contexts, persistence, defense evasion, and post-exploitation remote control. A trojanized XWorm builder has also been observed abusing Telegram Bot API functionality for both command-and-control and exfiltration, including theft of saved passwords, cookies, Discord tokens, and host information. In observed campaigns, XWorm payloads were delivered as .NET binaries and operated as the final-stage malware after loader execution. XWorm is best characterized as a financially motivated cybercrime tool rather than a nation-state threat actor. The name may refer both to the malware family itself and, in some reporting, to operators or campaigns deploying it. High-confidence reporting supports credential theft, exfiltration, persistence, process injection, defense evasion, and initial-access activity associated with XWorm operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A commodity .NET RAT deployed in this campaign as the final payload, providing credential theft, keylogging, webcam access, screenshot capture, USB propagation, and remote shell access.
Trojanized XWorm builder is used in campaigns for both exfiltration of sensitive data and command-and-control via Telegram’s bot API, supporting remote execution of commands and data theft.
Referenced as an example adversary associated with jli.dll side-loading for payload execution/defense evasion.
Associated with suspicious dynamic-DNS-based infrastructure, including duckdns and ddns domains, with repeated domain rotation and related domains resolving to the same IP/ASN. The content also links related infrastructure to a Remcos-labeled communicating file.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.