Researchers reported that XWorm, a .NET-based Windows remote access trojan, has been both actively deployed in phishing attacks and marketed online as a builder for criminal operators. The malware has been advertised with modules for RAT control, ransomware, HVNC, hidden RDP, DDoS, keylogging, credential theft, clipper functions, and persistence, while incident analysis found live samples communicating with command-and-control servers such as system6458[.]ddns[.]net over port 6666. Reverse engineering also showed that XWorm uses anti-analysis checks to terminate in virtualized or sandboxed environments and can persist through startup-folder copies, scheduled tasks, AppData placement, and registry autorun entries.
Separate investigations tied XWorm to ongoing delivery campaigns, including the MEME#4CHAN phishing operation, which used fake hotel reservation lures and Microsoft Word documents exploiting CVE-2022-30190 to launch multi-stage infection chains involving PowerShell, JScript, and in-memory .NET loading. Analysts found XWorm variants capable of PowerShell execution, in-memory .NET execution, screenshots, plugin retrieval, USB spreading, uninstall functions, and DDoS, with configuration fields such as Host, Port, and KEY encrypted using AES and derived keys. In some intrusions, the malware disabled AMSI, weakened Microsoft Defender, created a local administrator account named System32, disabled the Windows Firewall, and injected the final payload into processes including RegSvcs.exe and Msbuild.exe, with observed C2 infrastructure including 212.87.204[.]83:3000 and port3000newspm.duckdns[.]org.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The CERT Polska analysis documented XWorm capabilities including keylogging, USB spreading, uninstall, simple AV evasion, PowerShell execution, in-memory .NET execution, screenshots, plugin retrieval, and DDoS commands. It also listed recent XWorm C2 servers such as septiembre2022.duckdns.org:3130, 20.197.231.178:7000, and several other IP- and DuckDNS-based endpoints.
CERT Polska released a technical analysis of XWorm showing a malspam-delivered sample packed through multiple loader stages before unpacking the final .NET payload. The report explained that XWorm stores configuration in a static Settings class and encrypts fields such as Host, Port, KEY, SPL, and USBNM with AES-ECB using a key derived from the MD5 hash of the Mutex value.
The Securonix report described the campaign's post-exploitation behavior, including AMSI bypasses, Microsoft Defender exclusions, scheduled-task persistence, Startup-folder copies, and in some cases creation of a local administrator account named System32 and disabling of Windows Firewall. The final XWorm payload was observed executing in RegSvcs.exe or Msbuild.exe with C2 infrastructure including 212.87.204[.]83:3000 and port3000newspm.duckdns[.]org.
Securonix published analysis of the ongoing MEME#4CHAN campaign, which used phishing emails with malicious Word documents exploiting CVE-2022-30190 to deliver XWorm v3.1. The campaign used hotel-booking lures, targeted organizations including German businesses, and chained external relationship objects, PowerShell, JScript, and .NET loaders.
In the same analysis, Cyble said it identified active XWorm instances in the wild and described the malware as more prevalent and sophisticated than other EvilCoder Project samples it found. The report documented anti-analysis checks, persistence via startup folder/AppData/scheduled tasks/registry, and C2 communications to system6458[.]ddns[.]net:6666.
Cyble Research Labs discovered a dark web post advertising XWorm v2.2 and other offensive tools sold by a malware developer operating the EvilCoder Project website. The listing marketed XWorm as a .NET builder with RAT, ransomware, HVNC, hidden RDP, DDoS, keylogging, credential theft, clipper, and persistence features.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourcesecuronix.com
Open sourceblog.cyble.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.