Backdoor.MSIL.XWorm is a backdoor worm observed in phishing-driven campaigns affecting industrial control system (ICS/OT) environments. The provided reporting states it was the primary malware behind a global surge of email-borne worms in Q4 2025, after not being observed on ICS computers in Q3 2025, and then appearing across all world regions. It is described as establishing persistence on infected systems and giving attackers full remote control of compromised machines. The reporting further states that it can be used to monitor activity, move through networks, and potentially interfere with operational technology processes. The malware’s behavior was reportedly obfuscated using layered scripts and encoded payloads to evade standard detection.
The documented infection vector was primarily phishing email. The activity was linked to the long-running “Curriculum-vitae-catalina” campaign, in which attackers targeted HR managers, recruiters, and other hiring-related personnel with messages using subjects such as “Resume” or “Attached Resume.” The attachment was a malicious executable disguised as a CV, commonly named “Curriculum Vitae-Catalina.exe”; executing it infected the victim system. In Africa, the malware was also reported to spread via removable storage devices connected to ICS computers.
The campaign reportedly unfolded in two waves during October and November 2025, with activity subsiding in December. Regions specifically noted as heavily affected included Southern Europe, South America, and the Middle East; October activity also targeted Russia, Western Europe, South America, and Canada. In subsequent Q1 2026 ICS reporting, worm detections declined after the previous-quarter increase caused by phishing campaigns distributing Backdoor.MSIL.XWorm worldwide. The content does not attribute this malware to a specific named threat actor. Known indicators directly mentioned in the content include phishing lures with subjects “Resume” and “Attached Resume,” and the filename “Curriculum Vitae-Catalina.exe.”
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
In Africa, the worm also found a different path in through removable storage devices, reflecting how diverse the spread vectors became.
После роста показателя в предыдущем квартале (из-за очередной волны фишинговых атак, в ходе которых во всех регионах мира распространялся червь-бэкдор Backdoor.MSIL.XWorm)...
Attackers sent emails to HR managers, recruiters, and employees involved in hiring decisions, disguising malicious messages as job applications with subject lines such as “Resume” or “Attached Resume.” The emails carried a malicious executable file presented as a curriculum vitae, typically named Curriculum Vitae-Catalina.exe, which infected the system the moment it was opened.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm/backdoor malware family referenced as having been spread globally via phishing attacks, contributing to a prior-quarter increase in worm detections on ICS computers.
A backdoor worm spread via phishing emails disguised as job applications, establishing persistence and enabling full remote control of infected systems. In the described campaign it targeted ICS/OT environments globally and also spread via removable media in Africa.
A backdoor worm designed to persist on infected systems and enable remote control. In Q4 2025 it was observed spreading globally via phishing emails in the 'Curriculum-vitae-catalina' campaigns, and in some cases via removable media.
A backdoor worm distributed via phishing attacks, cited as the cause of a prior-quarter increase in worm detections across global ICS environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.