Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 296 IP / 338 hostnames
XWorm is a modular, multi-purpose .NET remote access trojan targeting Windows systems.
Profile source: Mallory opens in a new tabXWorm
XWorm is a modular, multi-purpose .NET remote access trojan targeting Windows systems. It is used for unauthorized remote control and supports command-and-control functions including execution of PowerShell, in-memory .NET payload execution, downloading and launching files, plugin retrieval, browser opening, system shutdown or logoff, and self-update or removal. Documented variants support keylogging, screenshot capture, clipboard monitoring, command-shell access, WMI-based host reconnaissance, USB propagation, and DDoS commands. XWorm also incorporates basic antivirus-evasion functionality and has been observed executing in memory through legitimate Windows processes.
XWorm has been delivered through phishing and malspam campaigns using malicious archives, JavaScript, Microsoft OneNote files, and Word documents. Observed delivery chains have relied on social-engineering themes such as invoices, tax notices, hotel reservations, shipping documents, and booking requests. Campaigns have used embedded OneNote objects, PowerShell loaders, public hosting services, and exploitation of CVE-2022-30190. The malware has also appeared as a payload in campaigns exploiting CVE-2025-8088.
XWorm is a commodity RAT deployed by multiple cybercriminal clusters. It has been associated with phishing activity attributed to TA558 and has also been linked to infrastructure and delivery activity tracked as DDGroup. Campaigns have targeted organizations globally, including businesses in Latin America and Europe; hospitality-themed campaigns have also affected manufacturing and healthcare organizations.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef 844255eae72a8865d0fd4da1ee1cd42a55543cc4c50776a71cc2c21467a3d279 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 17059be11c5449ed716d562af7f76f94e0535e47faaa483daef68d104bd8b4c3 39c8cc2adc34225c9c530a005672f89177f57c68a6198568db1df34224e8ee89 d35da97bbdffe16943dd45b6dae76185687f862564d71938f151ddb4017fd267 5c7ff654f528cc9e907abf27c1dcdc4a4053360c3986c1c22f1eafbfbfc05078 Reported operators
Final Payload: Publicly Available Trojan Families Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.
Panda was so kind to share the associated dll’s with me. And indeed, they turned out to be XWorm. Associated C2s: secoundxwormm.ddns[.]net freshinxworm.ddns[.]net
The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.
XClient3.exe (XWorm; 178.33.57.148:443)
Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.
The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.
XWORM RAT/Backdoor Windows UNC6032 Full remote access, C2 via Telegram.
TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.
A new rule detects DLL hijacking of the Java library jli.dll... a technique used by adversaries like APT41 and XWorm to execute payloads in a trusted process context.
...RATs... like RemcosRAT, QasarRat, AsyncRAT, and, XWorm...; “CRACKED BY hxxps[:]//t[.]me/xworm_v2”.
The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).
Exploited software
MITRE ATT&CK
Reporting
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file. The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.
Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.
Security researchers reported that ClickFix has expanded into an industrialized malware-delivery ecosystem that relies on social engineering rather than software exploits. Attackers use fake CAPTCHA checks, browser updates, meeting errors, and verification prompts to trick users into manually running attacker-supplied commands through trusted tools such as PowerShell, mshta, curl, Windows Run, or macOS Terminal. ReversingLabs said the ecosystem now supports a wide range of payloads, including Lumma Stealer, DarkGate, XWorm, AsyncRAT, NetSupport, and SectopRAT, while related variants such as CrashFix, FileFix, PromptFix, and ConsentFix continue to emerge. The activity is being amplified through large-scale web compromise campaigns. Reports linked the DriveSurge actor to active ClickFix and FakeUpdates operations abusing thousands of compromised websites to distribute malware, while a separate SlowMist investigation documented a Google Sites-hosted phishing campaign targeting Web3 users on macOS with a fake community application flow that pushed victims to download a .scpt file or run a Base64-encoded Terminal command. That infection chain delivered a Mach-O stealer resembling AMOS (Atomic macOS Stealer), which harvested browser credentials, cookies, Keychain data, Apple Notes, Telegram Desktop data, and cryptocurrency wallet files before archiving data to /tmp/lksopo.zip and exfiltrating it to 86.54.25.213. Researchers said structural YARA detection of lure pages is currently one of the most effective ways to identify these campaigns, which often evade traditional AV and EDR controls because they depend on legitimate tools and user-approved execution.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.