Researchers reported that XWorm re-emerged with the release of XWorm V6 after the malware had been widely considered abandoned, and that its latest campaigns used a modular plugin architecture to expand capabilities on infected Windows systems. In one observed chain, a malicious JavaScript file launched PowerShell, disabled AMSI, deployed an injector DLL, and injected the XWorm client into RegSvcs.exe, after which the malware contacted a command-and-control server at 94.159.113.64:4411. The malware stored plugins in the registry and retrieved them on demand to enable remote desktop control, shell access, credential theft, browser data theft, file management, persistence, and ransomware activity; researchers also linked some browser-theft components to public proof-of-concept code designed to bypass Chrome v20 protections.
Separate reporting found that threat actors were circulating a trojanized XWorm builder, underscoring infighting in the cybercrime ecosystem and showing that some operators and would-be customers were themselves being infected. Trellix likewise observed cracked and modified XWorm V6 builders, including leaked V6.4 variants containing Rootkit.dll and ResetSurvival.dll, and said some builders and operators had been compromised by XWorm malware. The malware’s persistence methods included logon scripts, Run keys, and abuse of ResetConfig.xml, while operators also deployed payloads such as DarkCloud Stealer, Remcos RAT, and other stealers; its ransomware plugin used AES-CBC, dropped a ransom note, changed the victim’s wallpaper, and showed code overlap with NoCry ransomware.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
A Hackforums post from the account XCoderTools announced XWorm V6.0 on June 4, 2025, claiming the new version fixed the prior remote code execution vulnerability affecting V5.6 and earlier.
After the June 2025 release of XWorm V6.0, Trellix observed a surge of related samples being uploaded to VirusTotal, indicating renewed activity around the malware family.
After releasing XWorm V5.6, XWorm developer XCoder disappeared in the latter half of 2024, contributing to the belief that the malware project had been abandoned.
XWorm was first observed in 2022 as a modular malware family built around a core client with multiple plugins.
Following XWorm's apparent abandonment, threat actors began distributing cracked or modified XWorm V5.6 versions, including trojanized builders.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.