Researchers reported renewed activity and fresh analysis of Hworm—also tracked as Houdini and njRAT—showing the long-running remote access trojan continuing to evolve from earlier Delphi-based campaigns into newer fileless delivery chains. Earlier campaigns used self-extracting archives with Middle East and Mediterranean political lures and decoy content while the malware ran in the background, and researchers tied some development to semi-public builder tooling and a Delphi rewrite discussed in underground forums. The malware family supports broad remote administration functions including keylogging, screenshot capture, file management, browser password theft, persistence, and process injection.
Recent analysis described a VBScript-based injector that uses DynamicWrapperX, base64-encoded components such as DCOM_DATA, LOADER_DATA, and FILE_DATA, and forced execution through 32-bit wscript.exe on 64-bit Windows systems before injecting the final payload into msbuild.exe. Across samples, Hworm/njRAT established persistence through the Windows Run registry key and copied itself into user-accessible paths, while command-and-control shifted from older HTTP-style traffic to mixed binary-and-ASCII TCP communications. Analysts also identified embedded configuration data including mutex values, installation paths, ports, and C2 infrastructure such as chroms.linkpc.net and 85.26.235.163:7777, alongside anti-analysis checks for tools including Wireshark, Process Hacker, dnSpy, Sandboxie, and VMware or VirtualBox services.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
On June 21, 2020, an analyst published analysis of an njRAT .NET sample that copied itself to multiple locations, created a Run key for persistence, and was configured to contact 85.26.235.163 on port 7777.
On September 13, 2019, jeFF0Falltrades published YARA rules and hashes for WSH RAT, described as a variant of H-Worm/Houdini. The rules covered the decoded VBScript component and .NET modules for keylogging, RDP, and reverse proxy functionality.
On October 25, 2016, Unit 42 published research on a new Hworm/Houdini variant used in multiple attacks. The report said the malware used a mixed binary-and-ASCII TCP protocol instead of the HTTP-based protocol seen in earlier versions.
Unit 42 assessed that a campaign using a new Delphi-based Hworm variant was active from at least June 2016 through mid-October 2016. The attacks used self-extracting archives with political-themed lures and decoy content while the malware executed in the background.
A password-protected beta builder for Delphi Hworm implants was uploaded to VirusTotal around October 2015. Unit 42 linked this builder to later Delphi-based Hworm development.
A user named "Houdini" posted on the Arabic-language forum dev-point[.]com around July 2015 describing plans to rewrite the backdoor in Delphi.
Hworm/njRAT was first seen in 2013 and was initially used in targeted attacks against the international energy sector in the Middle East before later becoming more broadly used.
Cofense published research describing Hworm/Houdini as part of a new phishing attack. This adds a phishing-delivery development not explicitly covered in the existing timeline.
Morphisec Labs reported a newly observed Hworm variant with a minor obfuscation change. The sample used a fileless VBScript injector with DynamicWrapperX and injected the final payload into msbuild.exe.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 51 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
cofense.com
Open sourceblog.morphisec.com
Open sourceisc.sans.edu
Open sourcemalwr-analysis.com
Open sourcegithub.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.