XWorm is a Windows remote access trojan that is frequently distributed through malspam campaigns using business-themed lures such as requests, quotations, orders, payments, documents, receipts, invoices, and offers. It has been repeatedly observed in campaigns targeting Italian-speaking users, where it appears alongside other commodity stealers and RATs such as AgentTesla, FormBook, Remcos, VIPKeylogger, PhantomStealer, and PureHVNC. XWorm has also been associated with distribution through unofficial file-sharing and webhard-style services, where operators disguise malware as legitimate software, games, or adult-themed content to entice execution.
Observed delivery chains indicate that XWorm can be staged through script, MSIL, WIN32, Office-document, and archive-based infection flows common to commodity malware operations. Related campaigns show the use of launcher and injector components that execute a decoy application while deploying the malware in parallel, followed by shellcode-based injection into legitimate Windows processes and tampering with Windows event logging mechanisms to reduce visibility. Similar tradecraft has been noted in ecosystems that also distribute XWorm, even when the final payload in a specific analyzed chain was another RAT.
At a functional level, XWorm is used for remote access and post-compromise control of infected systems. Reported capabilities associated with this malware family include collection of system information, keylogging, and file transfer, consistent with RAT activity and credential-focused surveillance. In operational reporting, XWorm is commonly grouped with password stealers and remote-access malware because it is used in credential-harvesting and broader hands-on-keyboard intrusion workflows.
XWorm is best characterized as a commodity Windows RAT used by opportunistic threat actors in phishing-driven campaigns rather than a tool tied exclusively to a single intrusion set or sector. Its recurring appearance in financially themed and business-process-themed email lures, together with its use in fake software and adult-content distribution schemes, reflects broad targeting and low barriers to adoption among cybercriminal operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT observed in malspam campaigns; the report groups it among password-stealer families and notes Italian-language lures themed around requests and receipts.
RAT-family malware observed in an Italian malspam campaign during the reporting week; included by the report among the week's password-stealer families.
RAT observed in an Italian-language malspam campaign targeting Italy, using a quotation-themed email lure.
XWormRAT is one of the malware families observed in the week's Italian malspam activity, delivered through payment-themed emails.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.