Skip to content

XWorm

XWorm is a modular, multi-purpose .NET remote access trojan targeting Windows systems.

Profile source: Mallory opens in a new tab

XWorm

Family profile

XWorm is a modular, multi-purpose .NET remote access trojan targeting Windows systems. It is used for unauthorized remote control and supports command-and-control functions including execution of PowerShell, in-memory .NET payload execution, downloading and launching files, plugin retrieval, browser opening, system shutdown or logoff, and self-update or removal. Documented variants support keylogging, screenshot capture, clipboard monitoring, command-shell access, WMI-based host reconnaissance, USB propagation, and DDoS commands. XWorm also incorporates basic antivirus-evasion functionality and has been observed executing in memory through legitimate Windows processes.

XWorm has been delivered through phishing and malspam campaigns using malicious archives, JavaScript, Microsoft OneNote files, and Word documents. Observed delivery chains have relied on social-engineering themes such as invoices, tax notices, hotel reservations, shipping documents, and booking requests. Campaigns have used embedded OneNote objects, PowerShell loaders, public hosting services, and exploitation of CVE-2022-30190. The malware has also appeared as a payload in campaigns exploiting CVE-2025-8088.

XWorm is a commodity RAT deployed by multiple cybercriminal clusters. It has been associated with phishing activity attributed to TA558 and has also been linked to infrastructure and delivery activity tracked as DDGroup. Campaigns have targeted organizations globally, including businesses in Latin America and Europe; hospitality-themed campaigns have also affected manufacturing and healthcare organizations.

Capabilities

  • Ddos
  • Defense Evasion
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
296 IP / 338 hostnames

Leading locations

  • US120
  • GB81
  • CN58
  • NL58
  • DE51
  • FR25
  • TR19
  • RU18
  • HK16
  • LU10
  • SA8
  • SG8

Leading providers

  • OOO GETWIFI68
  • Hangzhou Alibaba Advertising Co.,Ltd.30
  • Cloudflare, Inc.27
  • Oracle Corporation20
  • Fiba Cloud Operation Company, LLC17
  • HostPapa17

Infrastructure traits

  • Hosting 417
  • Anycast 34
  • Vpn 3

Samples

Recent associated samples

Reported operators

Threat actors

11 named in public reporting
TA558

Final Payload: Publicly Available Trojan Families Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.

DDGroup

Panda was so kind to share the associated dll’s with me. And indeed, they turned out to be XWorm. Associated C2s: secoundxwormm.ddns[.]net freshinxworm.ddns[.]net

Nullbulge

The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.

UAC-0184

XClient3.exe (XWorm; 178.33.57.148:443)

TA584

Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.

KongTuke

The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.

UNC6032

XWORM RAT/Backdoor Windows UNC6032 Full remote access, C2 via Telegram.

APT-C-36

TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.

APT41

A new rule detects DLL hijacking of the Java library jli.dll... a technique used by adversaries like APT41 and XWorm to execute payloads in a trusted process context.

Red Akodon

...RATs... like RemcosRAT, QasarRat, AsyncRAT, and, XWorm...; “CRACKED BY hxxps[:]//t[.]me/xworm_v2”.

PureCoder

The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).

Exploited software

Vulnerabilities linked to XWorm

5 CVEs

MITRE ATT&CK

XWorm in ATT&CK

120 distinct techniques

Techniques

120 techniques
T1123 Audio Capture T1204.002 Malicious File T1620 Reflective Code Loading T1059.001 PowerShell T1218.005 Mshta T1566.001 Spearphishing Attachment T1113 Screen Capture T1027 Obfuscated Files or Information T1204 User Execution T1583 Acquire Infrastructure T1566.002 Spearphishing Link T1059.007 JavaScript T1189 Drive-by Compromise T1608.006 SEO Poisoning T1566 Phishing T1105 Ingress Tool Transfer T1056.001 Keylogging T1125 Video Capture T1219 Remote Access Tools T1555 Credentials from Password Stores T1027.003 Steganography T1090.002 External Proxy T1006 Direct Volume Access T1564.003 Hidden Window T1059 Command and Scripting Interpreter T1571 Non-Standard Port T1547.001 Registry Run Keys / Startup Folder T1499 Endpoint Denial of Service T1203 Exploitation for Client Execution T1562 Impair Defenses T1071 Application Layer Protocol T1112 Modify Registry T1059.003 Windows Command Shell T1218 System Binary Proxy Execution T1091 Replication Through Removable Media T1568 Dynamic Resolution T1070 Indicator Removal T1027.010 Command Obfuscation T1053 Scheduled Task/Job T1098 Account Manipulation T1136.001 Local Account T1055 Process Injection T1573.001 Symmetric Cryptography T1568.003 DNS Calculation T1055.009 Proc Memory T1041 Exfiltration Over C2 Channel T1560 Archive Collected Data T1106 Native API T1070.004 File Deletion T1036 Masquerading T1562.001 Disable or Modify Tools T1059.005 Visual Basic T1027.007 Dynamic API Resolution T1622 Debugger Evasion T1202 Indirect Command Execution T1059.006 Python T1140 Deobfuscate/Decode Files or Information T1053.005 Scheduled Task T1021.001 Remote Desktop Protocol T1055.012 Process Hollowing T1136 Create Account T1082 System Information Discovery T1584.005 Botnet T1071.001 Web Protocols T1036.005 Match Legitimate Resource Name or Location T1565 Data Manipulation T1033 System Owner/User Discovery T1083 File and Directory Discovery T1057 Process Discovery T1486 Data Encrypted for Impact T1014 Rootkit T1539 Steal Web Session Cookie T1055.001 Dynamic-link Library Injection T1115 Clipboard Data T1518 Software Discovery T1007 System Service Discovery T1548 Abuse Elevation Control Mechanism T1037 Boot or Logon Initialization Scripts T1497.001 System Checks T1037.001 Logon Script (Windows) T1491 Defacement T1555.003 Credentials from Web Browsers T1497 Virtualization/Sandbox Evasion T1005 Data from Local System T1049 System Network Connections Discovery T1218.004 InstallUtil T1574.001 DLL T1195 Supply Chain Compromise T1498 Network Denial of Service T1001 Data Obfuscation T1213 Data from Information Repositories T1573 Encrypted Channel T1588.001 Malware T1102.002 Bidirectional Communication T1127.001 MSBuild T1548.002 Bypass User Account Control T1059.010 AutoHotKey & AutoIT T1656 Impersonation T1596.001 DNS/Passive DNS T1596.005 Scan Databases T1070.001 Clear Windows Event Logs T1567 Exfiltration Over Web Service T1047 Windows Management Instrumentation T1027.011 Fileless Storage T1055.004 Asynchronous Procedure Call T1218.011 Rundll32 T1518.001 Security Software Discovery T1547 Boot or Logon Autostart Execution T1056 Input Capture T1027.001 Binary Padding T1583.006 Web Services T1104 Multi-Stage Channels T1048 Exfiltration Over Alternative Protocol T1564.001 Hidden Files and Directories T1218.009 Regsvcs/Regasm T1218.001 Compiled HTML File T1021 Remote Services T1566.003 Spearphishing via Service T1195.001 Compromise Software Dependencies and Development Tools T1102.003 One-Way Communication

Reporting

Research mentioning XWorm

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Jul 22
Security Online Info

TTF Trap: Fake Font Files Hide a Stealthy Lua Loader

A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file. The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.

Jul 21
Cyber Security News

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.

Jul 21
Scworld

Sophisticated crypter service Cruciferra evades detection with advanced techniques | brief | SC Media

Jul 21
Gurucul Threat Research

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Community Portal | Gurucul

Jul 20
Dark Reading

Attackers Combo Up Evasion Tactics for BEC Phishing

Jul 18
Cyberveille

ClickFix : une méthodologie d'attaque industrialisée invisible aux EDR et antivirus | CyberVeille

Security researchers reported that ClickFix has expanded into an industrialized malware-delivery ecosystem that relies on social engineering rather than software exploits. Attackers use fake CAPTCHA checks, browser updates, meeting errors, and verification prompts to trick users into manually running attacker-supplied commands through trusted tools such as PowerShell, mshta, curl, Windows Run, or macOS Terminal. ReversingLabs said the ecosystem now supports a wide range of payloads, including Lumma Stealer, DarkGate, XWorm, AsyncRAT, NetSupport, and SectopRAT, while related variants such as CrashFix, FileFix, PromptFix, and ConsentFix continue to emerge. The activity is being amplified through large-scale web compromise campaigns. Reports linked the DriveSurge actor to active ClickFix and FakeUpdates operations abusing thousands of compromised websites to distribute malware, while a separate SlowMist investigation documented a Google Sites-hosted phishing campaign targeting Web3 users on macOS with a fake community application flow that pushed victims to download a .scpt file or run a Base64-encoded Terminal command. That infection chain delivered a Mach-O stealer resembling AMOS (Atomic macOS Stealer), which harvested browser credentials, cookies, Keychain data, Apple Notes, Telegram Desktop data, and cryptocurrency wallet files before archiving data to /tmp/lksopo.zip and exfiltrating it to 86.54.25.213. Researchers said structural YARA detection of lure pages is currently one of the most effective ways to identify these campaigns, which often evade traditional AV and EDR controls because they depend on legitimate tools and user-approved execution.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.