XWorm is a commodity Windows remote-access trojan (RAT), including versions 3.1 and 6.0, sold in cybercrime markets and also available through leaked or cracked builds. It provides operators with remote control of compromised systems and supports command-shell access, PowerShell execution, file download and execution, update and uninstall operations, browser launching, screenshot capture, clipboard monitoring, socket communications, host reconnaissance, system power actions, and denial-of-service functionality. XWorm has been observed in campaigns establishing persistence through Startup-folder modifications and scheduled tasks, and in-memory execution within legitimate Windows processes. Campaigns have also used XWorm alongside actions to impair Windows security controls and establish elevated local access. XWorm has been delivered through phishing campaigns using malicious Microsoft Office and OneNote documents, compressed archives, JavaScript files disguised as tax or business documents, and compromised websites. It has appeared in financially motivated activity against Brazilian financial-services, retail, e-commerce, and payment-sector organizations; hospitality-themed phishing attributed to TA558; campaigns targeting German organizations; and phishing activity targeting Colombia and the surrounding region. The malware is also associated with infrastructure attributed to the DDGroup cybercrime cluster. Reported use includes remote control and theft of sensitive information, including browser credentials and keystrokes, in commodity-malware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw. | Xworm – Sample File name: rockstaracc.rar
Rather than using macros to execute malicious VBscript, this document uses a known vulnerability from last year (CVE-2022-30190). In summary, this vulnerability works by embedding external objects contained in a relationship file within the .docx word file. | The attack campaign (tracked by Securonix as MEME#4CHAN) was leveraging rather unusual meme-filled PowerShell code, followed by a heavily obfuscated XWorm payload to infect its victims.
Recent Xworm campaigns have leveraged multiple file formats and scripting languages, including PowerShell, VBS, HTA, and Office macro exploits such as CVE-2018-0802, to stage payloads and evade endpoint defenses. | Xworm followed closely with 183 uploads... continuing its reputation as a highly adaptable, modular RAT sold through malware-as-a-service channels.
1014578922 INV_PL SWB Specimen.xlam Invoice CVE-2017-11882 2026-03-24 | A Turkish-origin threat actor operating under the GitHub alias flexhere687-art ... is conducting an active XWorm V6.0 campaign using a multi-layered delivery chain.
Tearing apart a .NET crypter to extract dual XWorm RAT payloads, then decompiling the RAT to find a UEFI bootkit with BlackLotus DBX bypass, an r77 rootkit, driver infection, CVE-2026-20817 zero-day UAC bypass, and D/Invoke API evasion.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Utilisation de sites gouvernementaux brésiliens compromis pour héberger des infostealers déguisés en documents fiscaux ... et des backdoors (XWORM).
Final Payload: Publicly Available Trojan Families Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.
Panda was so kind to share the associated dll’s with me. And indeed, they turned out to be XWorm. Associated C2s: secoundxwormm.ddns[.]net freshinxworm.ddns[.]net
The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.
Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
These fake CAPTCHAs arrive via phishing emails, URL redirection or malvertisement, or SEO poisoning.
“GTIG observed BREEZE COMET using compromised Brazilian small government websites to stage RMM tools... [and] as C2 endpoints.”
Users encounter a CAPTCHA page that mimics a legitimate human verification prompt, often while browsing seemingly harmless content websites.
« Utilisation de sites gouvernementaux brésiliens compromis pour héberger des infostealers ... et des backdoors »
These fake CAPTCHAs arrive via phishing emails, URL redirection or malvertisement, or SEO poisoning.
“A self-extracting archive launched VBScript and hidden PowerShell, wrote script content into ProgramData, then reached InstallUtil.exe.”
a user was identified downloading a malicious JavaScript file, which was impersonating a tax document; the user was directed to the download page via a malicious email.
This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw.
When lyricalsync.mp3 is executed via mshta, it initiates a multistage deobfuscation process designed to evade detection mechanisms.
The most distinctive characteristic of TA558's recent attack campaigns... is the concealment of malicious PowerShell code or payloads within seemingly innocuous JPG images.
“infostealers disguised as legitimate tax or receipt documents (e.g., ComprovantePDF.exe)”
“[The chain] then reached InstallUtil.exe, a signed Windows utility that can be abused to run malicious code.”
the group primarily used the archive.org data platform and the Cloudinary video platform... leveraged legitimate cloud storage services ... as payload distribution channels
“Related samples contacted code repositories and cloud storage” and “The operation can move files between familiar services.”
832 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor staged from compromised websites as part of Breeze Comet operations.
Backdoor hosted on compromised Brazilian government websites as part of BREEZE COMET's initial-access infrastructure.
Remote-access malware found among recovered operator artifacts, consistent with an operational capability to vary RAT payloads and delivery routes.
Remote-access trojan represented by versioned build entries in the operator's internal payload dispatch list.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.