XWorm is a Windows remote access trojan used in commodity cybercrime operations and frequently delivered through phishing and ClickFix-style social engineering chains, as well as through loaders, crypters, and staged script-based infection flows. It has been observed in campaigns using malicious archives, disk images, shortcut files, JavaScript, VBScript, batch scripts, PowerShell, Lua-based loaders, Python-based loaders, and fileless in-memory execution. Delivery themes have included tax notices, business documents, fake IT support prompts, invoice lures, and steganography-themed decoys. XWorm has also appeared as a payload delivered by malware-enablement services and loaders such as Cruciferra and in campaigns abusing trusted or compromised web infrastructure.
The malware is characterized by modular RAT functionality that enables persistent remote control of infected systems. Reported capabilities include keylogging, credential and data theft, remote payload execution, host reconnaissance, persistence, and exfiltration. XWorm infections have been associated with startup-folder and autorun persistence, scheduled-task creation, hidden or obfuscated execution, reflective or in-memory .NET assembly loading, and encrypted command-and-control communications. Multiple analyses describe extensive defense evasion through script obfuscation, AMSI bypass, event logging tampering, junk code insertion, runtime string reconstruction, anti-analysis checks, API unhooking, and process injection, including APC-based techniques and injection into legitimate Windows processes.
Operationally, XWorm is commonly used as a follow-on payload in broad phishing campaigns and social-engineering ecosystems rather than as a bespoke intrusion platform. It has been observed alongside other commodity malware families including AsyncRAT, Remcos, Agent Tesla, Lumma, DarkGate, NetSupport, SectopRAT, VenomRAT, and AdaptixC2. Campaign reporting links XWorm delivery to opportunistic targeting across sectors such as financial services, healthcare, government, hospitality, travel, and general enterprise users. Some observed intrusions used XWorm as one of several redundant access mechanisms, supporting sustained hands-on-keyboard activity and data theft after initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2025-12 FortiGuard [[URL_5ad24528_9]] Multi-themed phishing, Equation Editor CVE-2018-0802 abuse | → XWorm RAT (XClient variant) process-hollowed into Caspol.exe → C2: alzap.ddns.com.br on a Brazilian Telefonica residential IP
1014578922 INV_PL SWB Specimen.xlam Invoice CVE-2017-11882 2026-03-24 | A Turkish-origin threat actor operating under the GitHub alias flexhere687-art ... is conducting an active XWorm V6.0 campaign using a multi-layered delivery chain.
Tearing apart a .NET crypter to extract dual XWorm RAT payloads, then decompiling the RAT to find a UEFI bootkit with BlackLotus DBX bypass, an r77 rootkit, driver infection, CVE-2026-20817 zero-day UAC bypass, and D/Invoke API evasion.
Google also observed financially motivated actors exploiting the WinRAR path-traversal flaw to distribute commodity remote access tools and information stealers such as XWorm and AsyncRAT...
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
[👽TA] TA558 (🏴): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)
The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.
Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.
The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
In observed campaigns, malware is delivered via email, with Cruciferra used to obfuscate the ultimate payload.
The script reconstructs the hidden command at runtime, then leverages WMI (Win32_Process and Win32_ProcessStartup) to create and execute a process silently.
Finally, we identified that this Windows Script Host (JScript) code establishes persistence...
finally uses the PS1 to load a malicious embedded payload and connects to the attacker’s Command & Control (C2) server.
The file WordDoc.bat runs and injects and executes injection code... In Batch, the %randomCharacters% like %ltc% are used by the malicious code... attackers abuse it for obfuscation to do delayed expansion.
This malware sample uses VBScript to create a batch file, WordDoc.bat.
APT44’s ASPX web shell leverages obfuscation techniques ... Unveiling APT28’s Advanced Obfuscated Loader and HTA Trojan ... Deobfuscating APT28’s HTA Trojan: A Deep Dive into VBE Techniques & Multi-Layer Obfuscation ... XWorm Unmasked: Weaponizing Script Obfuscation and Modern Evasion Techniques
This indicates a fileless execution technique where the payload is retrieved and executed dynamically.
The landing pages... were designed to closely mimic legitimate government tax portals and prompt the recipient to download required documents which reinforce legitimacy and urgency.
finally decompressing it and then executing it in memory... it avoids file drops (fileless).
the first thing to do is to read the injection string from the batch file and to decode it with base64... And the second thing is to read the embedded malicious code from the batch file and to decode it, combining both Base64 and AES algorithms, and finally decompressing it
401 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT observé comme payload livré via ClickFix.
Remote access malware delivered by the campaign's Lua-based loader.
Referenced only as a comparison in cleanup guidance for similar endpoint checks.
A remote access trojan delivered by Cruciferra in an SSA-themed campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.