XWorm is a modular .NET remote access trojan that emerged in 2022 and is widely distributed through malware-as-a-service channels. It primarily targets Windows systems and is used by cybercriminal operators for unauthorized remote access, credential theft, keylogging, surveillance, and follow-on payload delivery. Reported feature sets include theft of credentials and cryptocurrency-related data, webcam access, distributed denial-of-service functionality, and plugins that enable ransomware deployment. XWorm command traffic has been observed using AES encryption, reflecting ongoing efforts to hinder inspection and analysis.
XWorm commonly appears in multi-stage intrusion chains rather than as a standalone first-stage implant. Observed delivery methods include phishing and spearphishing campaigns using malicious archives, JavaScript, LNK files, PowerShell-based stages, and themed social-engineering lures such as government notices, tax-related messages, shipping or business communications, and fake support or verification prompts. It has also been delivered through ClickFix-style lures that trick users into executing attacker-supplied commands, as well as through exploit-assisted delivery involving vulnerabilities such as CVE-2025-8088 and CVE-2018-0802. In some campaigns, XWorm is protected or deployed by third-party loaders and crypters, including Lua- or AutoIt-based fileless loaders and the Cruciferra crypter service, which use obfuscation, in-memory execution, and process injection to reduce detection.
Operationally, XWorm is associated with commodity cybercrime activity rather than a single exclusive threat actor. It has been observed in broad phishing campaigns, malware telemetry, and Telegram-linked malware ecosystems, and has appeared alongside other commodity families such as AsyncRAT, Remcos, Agent Tesla, Lumma, and zgRAT. Campaign reporting shows use against a wide range of sectors, including government, hospitality, travel, finance, and general enterprise users, typically in opportunistic rather than narrowly targeted operations. In hands-on-keyboard scenarios, XWorm enables persistence, data theft, and broader post-compromise activity, making it a flexible access and monetization tool within the contemporary cybercrime ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
des emails de phishing contenant des fichiers Excel exploitant la vulnérabilité CVE-2018-0802 | XWorm est un cheval de Troie d’accès à distance (RAT) basé sur .NET, apparu en 2022, et qui continue d’évoluer avec des mécanismes de diffusion de plus en plus sophistiqués, ciblant principalement les systèmes Windows.
The 2026 infection chain begins with phishing emails containing ZIP attachments ... and newer variants exploit the WinRAR flaw CVE-2025-8088 ... Common Vulnerabilities Exploited (CVEs) ... CVE-2025-8088 WinRAR path traversal leading to arbitrary code execution XWorm | XWorm is a modular RAT sold through malware-as-a-service channels since 2022, offering credential theft, keylogging, webcam access, DDoS, and ransomware-deployment plugins.
AsyncRAT ... Exploitation of CVE-2022-30190 (Follina/MSDT “Dogwalk”) for arbitrary code execution ... Xworm ... Exploitation of the Follina vulnerability CVE-2022-30190 via malicious .docx files | Xworm is a modular, MaaS-distributed RAT first seen in July 2022... capable of ransomware deployment, DDoS, and cryptocurrency/credential theft.
1014578922 INV_PL SWB Specimen.xlam Invoice CVE-2017-11882 2026-03-24 | A Turkish-origin threat actor operating under the GitHub alias flexhere687-art ... is conducting an active XWorm V6.0 campaign using a multi-layered delivery chain.
Tearing apart a .NET crypter to extract dual XWorm RAT payloads, then decompiling the RAT to find a UEFI bootkit with BlackLotus DBX bypass, an r77 rootkit, driver infection, CVE-2026-20817 zero-day UAC bypass, and D/Invoke API evasion.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
[👽TA] TA558 (🏴): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)
The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.
Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.
The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
plusieurs campagnes utilisent XWorm, notamment via : des packages npm malveillants
Il exécute généralement des attaques en plusieurs étapes, en utilisant souvent des tactiques d'hameçonnage impliquant des fichiers LNK malveillants et des scripts PowerShell pour se déployer via des outils légitimes.
...des fichiers LNK malveillants et des scripts PowerShell pour se déployer via des outils légitimes.
followed by JS and BAT scripts that ultimately deploy Python-based loaders... extracting a malicious JavaScript loader
MSBuild.exe abused by XWorm and Remcos for reflective DLL injection and payload execution
Persistence is established through startup-folder batch scripts and code injection into explorer.exe... The payload is injected into MSBuild.exe or Aspnet_compiler.exe via process hollowing for fileless execution
payloads embedded in JPEG and TXT files for in-memory execution... obfuscated JavaScript embedded in PDFs
with payloads embedded in JPEG and TXT files for in-memory execution... retrieves a Base64-encoded DLL appended to a JPEG hosted on public image services
plusieurs campagnes utilisent XWorm, notamment via : ... de faux jeux vidéo.
Persistence is established through startup-folder batch scripts and code injection into explorer.exe... The payload is injected into MSBuild.exe or Aspnet_compiler.exe via process hollowing for fileless execution
Le malware utilise des techniques avancées comme le process hollowing, permettant d’injecter son code dans des processus légitimes tels que « MSBuild ou Windows Explorer »
MSBuild.exe abused by XWorm and Remcos for reflective DLL injection and payload execution
For instance, in the case of the XWorm malware infection I examined, this Remote Access Trojan (RAT) encrypts commands sent from the Command and Control (C2) server using the AES encryption algorithm in ECB mode, making the payload unreadable.
For instance, in the case of the XWorm malware infection I examined, this Remote Access Trojan (RAT) encrypts commands sent from the Command and Control (C2) server using the AES encryption algorithm in ECB mode, making the payload unreadable.
L’API Telegram Bot est massivement exploitée par des auteurs de malwares comme canal d’exfiltration et de commande/contrôle (C2).
Le principe : un token bot et un chat_id embarqués dans le binaire permettent d’envoyer les données volées directement dans un chat Telegram via api.telegram.org, sans infrastructure propre à gérer.
retrieves a Base64-encoded DLL appended to a JPEG hosted on public image services
561 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan that encrypts commands sent from its C2 server, making payload inspection unreadable in packet analysis.
A malware family cited as a historical example of multi-stage remote access trojans.
A remote access trojan family referenced as an example of established multi-stage RAT malware.
Remote access trojan identified as one of the dominant Telegram-C2 malware families in the dataset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.