H-Worm, also known as Houdini, is a Windows remote access trojan that emerged in 2013 and has been used both in targeted espionage activity and in broader criminal campaigns. Early reporting linked it to attacks against the international energy sector in the Middle East, while later use showed commoditization among lower-sophistication operators, including spam-phishing and business-email-compromise-adjacent activity. It has also appeared in operations associated with Palestinian threat activity and as an auxiliary payload used by other malware operators.
H-Worm has existed in multiple implementation styles, including earlier script-based variants using obfuscated VBScript or AutoIT components and later Delphi-based variants. Observed delivery chains include self-extracting archives themed around regional political topics that launch decoy documents, videos, or web content while the malware runs in the background, as well as VBScript-based loaders that decode embedded components, register DynamicWrapperX, and execute RunPE-style shellcode for process injection. The malware has been observed establishing persistence through user autorun mechanisms and dropping copies of its loader into user-profile locations.
Functionally, H-Worm provides full remote administration of infected systems. Documented capabilities include keylogging, screenshot capture, file management, process and module management, download-and-execute, browser password theft, and USB device notification. Some variants steal credentials from major browsers and can inject payloads into legitimate Windows processes for stealth. Later Delphi variants used a TCP-based command-and-control protocol distinct from older HTTP-based implementations.
H-Worm is best characterized as a commodity RAT/backdoor family available beyond a single actor, enabling use by both targeted threat groups and financially motivated operators. Its long lifespan, multiple rewrites, and flexible loader ecosystem have made it a recurring tool in Middle Eastern intrusion activity and in broader Windows-focused malware campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This group occasionally deployed publicly available malware for Windows, including NJRat and HWorm, commonly used in the region.
A new occurrence was Hworm, which was first seen in SilverTerrier attacks in 2018 despite being available since 2013.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
As the script executes it first adds one of three startup methods which will execute the script on Windows startup: ... Startup task ( not implemented yet )
It allows to call functions exported by DLL libraries, in particular Windows API functions, from JScript and VBScript.
The payload is a VBS file, which, in some cases, comes obfuscated or encoded with couple of layers.
As the script executes it first adds one of three startup methods which will execute the script on Windows startup: ... Startup task ( not implemented yet )
The payload is a VBS file, which, in some cases, comes obfuscated or encoded with couple of layers.
The original filenames of these delivery files are related to political figures and groups in the Middle East and the Mediterranean.
The second stage is basically FILE_DATA which is injected to ‘msbuild.exe’ using LOADER_DATA (RunPE).
It will then register DynamicWrapperX: regsvr32 . exe / I / S < filename_dynamic_wrapperx >
The script checks whether the current environment is 64bit or not. If it is, it will execute the script with a 32-bit version of wscript.exe (from SysWOW64).
It includes the string “new_houdini”, the mutex used by the implant, the name of the user, the operating system version, the version of the implant, and the name of the foreground process
It includes the string “new_houdini”, the mutex used by the implant, the name of the user, the operating system version, the version of the implant, and the name of the foreground process
Misc : Provides the ability to list processes or modules and kill running processes
It includes the string “new_houdini”, the mutex used by the implant, the name of the user, the operating system version, the version of the implant, and the name of the foreground process
This new version of Hworm uses a mixed binary and ASCII protocol over TCP.
If the key is not found, the client sends a 'sendplugin' command to the C2 server ... The C2 server then responds with the command 'savePlugin' along with a base64 encoded string containing the plugin | We observed XWorm RAT Operators execute additional malware, such as: DarkCloud Stealer ... Remcos RAT
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VBS-based remote access trojan additionally executed by XWorm operators.
A remote access trojan that gives attackers complete control of the victim system. In this report it is delivered via an obfuscated VBScript-based fileless injector using DynamicWrapperX and RunPE, establishes persistence via the Run registry key, and injects its payload into processes such as msbuild.exe.
Publicly available Windows malware used by the PSS-linked group; described as commonly used in the region.
Remote access trojan newly observed in SilverTerrier attacks in 2018, used to support BEC operations with remote administration capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.