Skip to content
Malware family Windows

XWorm

XWorm is a Windows remote access trojan used in commodity malware campaigns and criminal intrusion operations.

Profile source: Mallory opens in a new tab

XWorm

Family profile

XWorm is a Windows remote access trojan used in commodity malware campaigns and criminal intrusion operations. It is commonly delivered through phishing and related social-engineering chains, including archive-based email lures, ClickFix-style fake verification or support prompts, and multi-stage script loaders using JScript, VBScript, batch, PowerShell, AutoIt, Lua, Python, or MSI-based staging. It has also appeared as a secondary payload distributed by broader malware ecosystems such as Amadey and alongside other commodity malware families including Lumma, AsyncRAT, Remcos, DarkGate, NetSupport, and SectopRAT.

Observed XWorm infection chains emphasize fileless or low-artifact execution and layered obfuscation. Documented loaders reconstruct payloads at runtime, decode embedded content, disable or evade AMSI and Windows event logging, load .NET assemblies directly into memory through reflection, and use process injection techniques including APC-based injection. Script-based variants have used persistence through the Startup folder, scheduled tasks, and autorun mechanisms. Some campaigns have used steganography-themed lures and staged retrieval of additional payload components before executing the final RAT.

XWorm provides remote access and post-compromise control over infected hosts. Reported behavior and campaign usage support capabilities including persistence, keylogging, credential and data theft, exfiltration, process injection, and broader post-exploitation activity. In ClickFix-related operations and hands-on-keyboard intrusions, XWorm has been associated with sustained access, redundant footholds, and operator-driven activity such as lateral movement and data theft. Some observed deployments have also used Telegram as an exfiltration or operator communications channel.

The malware is widely treated as a commodity RAT rather than a tool exclusive to a single threat actor. It has been observed in global phishing campaigns impersonating businesses or government entities, in tax-themed and invoice-themed lures, and in steganography-enabled delivery chains. Targeting is opportunistic and broad, with affected victims including enterprises, public-sector users, and general Windows users.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
124 IP / 106 hostnames

Leading locations

  • US48
  • NL28
  • DE27
  • CN20
  • GB19
  • HK10
  • RU8
  • LU6
  • TR6
  • FR5
  • KR5
  • CA3

Leading providers

  • OOO GETWIFI15
  • HostPapa9
  • Cloudflare, Inc.8
  • Hangzhou Alibaba Advertising Co.,Ltd.8
  • Developed Methods LLC6
  • Ghosty Networks LLC6

Infrastructure traits

  • Hosting 172
  • Anycast 16
  • Vpn 9
  • Proxy 5
  • Mobile 3
  • Residential Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

11 named in public reporting
TA558

[👽TA] TA558 (🏴): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)

Nullbulge

The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.

TA584

Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.

KongTuke

The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.

UNC6032

XWORM RAT/Backdoor Windows UNC6032 Full remote access, C2 via Telegram.

APT-C-36

TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.

APT41

A new rule detects DLL hijacking of the Java library jli.dll... a technique used by adversaries like APT41 and XWorm to execute payloads in a trusted process context.

Red Akodon

...RATs... like RemcosRAT, QasarRat, AsyncRAT, and, XWorm...; “CRACKED BY hxxps[:]//t[.]me/xworm_v2”.

PureCoder

The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).

Exploited software

Vulnerabilities linked to XWorm

4 CVEs

MITRE ATT&CK

XWorm in ATT&CK

116 distinct techniques

Techniques

116 techniques
T1566 Phishing T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link T1219 Remote Access Tools T1204 User Execution T1656 Impersonation T1596.001 DNS/Passive DNS T1596.005 Scan Databases T1140 Deobfuscate/Decode Files or Information T1620 Reflective Code Loading T1070.001 Clear Windows Event Logs T1059.001 PowerShell T1562 Impair Defenses T1027 Obfuscated Files or Information T1059.003 Windows Command Shell T1059.005 Visual Basic T1071 Application Layer Protocol T1547.001 Registry Run Keys / Startup Folder T1204.002 Malicious File T1567 Exfiltration Over Web Service T1047 Windows Management Instrumentation T1027.011 Fileless Storage T1112 Modify Registry T1105 Ingress Tool Transfer T1564.003 Hidden Window T1056.001 Keylogging T1059 Command and Scripting Interpreter T1055.004 Asynchronous Procedure Call T1218.011 Rundll32 T1055 Process Injection T1059.007 JavaScript T1218.005 Mshta T1106 Native API T1059.006 Python T1518.001 Security Software Discovery T1033 System Owner/User Discovery T1082 System Information Discovery T1036.005 Match Legitimate Resource Name or Location T1497.001 System Checks T1071.001 Web Protocols T1053.005 Scheduled Task T1218 System Binary Proxy Execution T1036 Masquerading T1189 Drive-by Compromise T1573 Encrypted Channel T1547 Boot or Logon Autostart Execution T1560 Archive Collected Data T1056 Input Capture T1053 Scheduled Task/Job T1027.001 Binary Padding T1195 Supply Chain Compromise T1486 Data Encrypted for Impact T1583.006 Web Services T1562.001 Disable or Modify Tools T1104 Multi-Stage Channels T1048 Exfiltration Over Alternative Protocol T1564.001 Hidden Files and Directories T1218.009 Regsvcs/Regasm T1127.001 MSBuild T1055.012 Process Hollowing T1218.001 Compiled HTML File T1027.003 Steganography T1497 Virtualization/Sandbox Evasion T1021.001 Remote Desktop Protocol T1021 Remote Services T1136 Create Account T1041 Exfiltration Over C2 Channel T1566.003 Spearphishing via Service T1195.001 Compromise Software Dependencies and Development Tools T1070.004 File Deletion T1499 Endpoint Denial of Service T1005 Data from Local System T1203 Exploitation for Client Execution T1083 File and Directory Discovery T1518 Software Discovery T1102.003 One-Way Communication T1113 Screen Capture T1555.003 Credentials from Web Browsers T1204.001 Malicious Link T1564 Hide Artifacts T1125 Video Capture T1555 Credentials from Password Stores T1027.002 Software Packing T1498 Network Denial of Service T1568.002 Domain Generation Algorithms T1102 Web Service T1562.006 Indicator Blocking T1090.002 External Proxy T1027.013 Encrypted/Encoded File T1571 Non-Standard Port T1562.003 Impair Command History Logging T1091 Replication Through Removable Media T1055.003 Thread Execution Hijacking T1665 Hide Infrastructure T1583.001 Domains T1016 System Network Configuration Discovery T1090.003 Multi-hop Proxy T1553.002 Code Signing T1102.001 Dead Drop Resolver T1583.003 Virtual Private Server T1027.005 Indicator Removal from Tools T1115 Clipboard Data T1572 Protocol Tunneling T1622 Debugger Evasion T1057 Process Discovery T1218.004 InstallUtil T1059.010 AutoHotKey & AutoIT T1036.007 Double File Extension T1548 Abuse Elevation Control Mechanism T1197 BITS Jobs T1573.001 Symmetric Cryptography T1529 System Shutdown/Reboot T1027.010 Command Obfuscation T1614.001 System Language Discovery T1583.004 Server T1132.001 Standard Encoding

Reporting

Research mentioning XWorm

Jul 20
Dark Reading

Attackers Combo Up Evasion Tactics for BEC Phishing

The campaign, dubbed "The TFF Trap," uses a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private Logger.

Jul 18
Cyberveille

ClickFix : une méthodologie d'attaque industrialisée invisible aux EDR et antivirus | CyberVeille

Payloads observés # Lumma Stealer (payload le plus fréquent) XWorm, AsyncRAT, NetSupport, SectopRAT, DarkGate (RATs)

Jul 17
Gurucul Threat Research

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | Community Portal | Gurucul

Since late March 2026, researchers have observed large-scale phishing campaigns that use fileless techniques and Lua-based loaders with low detection rates to deliver malware such as Agent Tesla, Remcos, XWorm, and Best Private LOGGER.

Jul 16
Trojan Killer News

PhantomEnigma Backdoor Uses Hijacked Government Sites

Our guides on fake IT support MSI backdoors, SmartRAT banking-lure cleanup, and fake tax notice XWorm infections cover similar endpoint checks.

Jul 16
Proofpoint

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Proofpoint US

These messages contained URLs leading to the download of a VHD file which, if clicked, ran an executable which ran Cruciferra. This malware then led to XWorm and AdaptixC2.

Jul 16
Fortinet Threat Research

The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | FortiGuard Labs

Since late March, 2026, we have been observing large-scale campaigns that use a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER.

Jul 15
Help Net Security

ClickFix is changing the economics of social engineering - Help Net Security

Remote access trojans including DarkGate, XWorm, AsyncRAT, NetSupport, and SectopRAT are also in the ClickFix rotation, enabling hands-on-keyboard activity such as lateral movement, persistence, and data exfiltration.

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

XWorm8

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.