Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 124 IP / 106 hostnames
XWorm is a Windows remote access trojan used in commodity malware campaigns and criminal intrusion operations.
Profile source: Mallory opens in a new tabXWorm
XWorm is a Windows remote access trojan used in commodity malware campaigns and criminal intrusion operations. It is commonly delivered through phishing and related social-engineering chains, including archive-based email lures, ClickFix-style fake verification or support prompts, and multi-stage script loaders using JScript, VBScript, batch, PowerShell, AutoIt, Lua, Python, or MSI-based staging. It has also appeared as a secondary payload distributed by broader malware ecosystems such as Amadey and alongside other commodity malware families including Lumma, AsyncRAT, Remcos, DarkGate, NetSupport, and SectopRAT.
Observed XWorm infection chains emphasize fileless or low-artifact execution and layered obfuscation. Documented loaders reconstruct payloads at runtime, decode embedded content, disable or evade AMSI and Windows event logging, load .NET assemblies directly into memory through reflection, and use process injection techniques including APC-based injection. Script-based variants have used persistence through the Startup folder, scheduled tasks, and autorun mechanisms. Some campaigns have used steganography-themed lures and staged retrieval of additional payload components before executing the final RAT.
XWorm provides remote access and post-compromise control over infected hosts. Reported behavior and campaign usage support capabilities including persistence, keylogging, credential and data theft, exfiltration, process injection, and broader post-exploitation activity. In ClickFix-related operations and hands-on-keyboard intrusions, XWorm has been associated with sustained access, redundant footholds, and operator-driven activity such as lateral movement and data theft. Some observed deployments have also used Telegram as an exfiltration or operator communications channel.
The malware is widely treated as a commodity RAT rather than a tool exclusive to a single threat actor. It has been observed in global phishing campaigns impersonating businesses or government entities, in tax-themed and invoice-themed lures, and in steganography-enabled delivery chains. Targeting is opportunistic and broad, with affected victims including enterprises, public-sector users, and general Windows users.
C2 tracking
Derp observations, rolling seven-day window
Samples
d24f85484931015b4a8ec88260b40c1b9d6ea4bf24645d026d5827b098fff935 1ceab9e717de6a434a2889a81c47de9452fcca6a106089649229875e4dac3844 27dc2e511f4da03bc10b975156996133c8654defc24d40b829ff7d955be4e2ce 2e74827318235a497133219963a2205cd8d7779a195ec67d740d825599210932 5594d4a2153e25d5de0de21bc958e1d11a341679ea2fec2123567fa3547c7847 7ef34bf0c59089432586e8847b5a8d7439a28ed3aca3254fab49ef13723be65e c4617e465670873ca7de2d8898e8c349d8189b86561fc5b8996c4d8bab251801 18e524fb9be61b8e8408eae149c3512584c3185bcc7d4ba77bcf591edf4b8612 1d962b488c95c5e9fa41ad5428a83581b426567ab9b2cf053ec78cf00b539bff 64285094d2a6f543433d9b2bbac04cc93be0bfeb0ba2fbafb8d2f239f64a347b Reported operators
[👽TA] TA558 (🏴): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)
The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.
XClient3.exe (XWorm; 178.33.57.148:443)
Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.
The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.
XWORM RAT/Backdoor Windows UNC6032 Full remote access, C2 via Telegram.
TAG-144 has employed a wide array of open-source and cracked RATs, including AsyncRAT, DcRAT, REMCOS RAT, XWorm, and LimeRAT, among others.
...Ongoing MEME#4CHAN Attack/Phishing Campaign... Drop XWorm Payloads
A new rule detects DLL hijacking of the Java library jli.dll... a technique used by adversaries like APT41 and XWorm to execute payloads in a trusted process context.
...RATs... like RemcosRAT, QasarRat, AsyncRAT, and, XWorm...; “CRACKED BY hxxps[:]//t[.]me/xworm_v2”.
The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).
Exploited software
MITRE ATT&CK
Reporting
The campaign, dubbed "The TFF Trap," uses a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private Logger.
Payloads observés # Lumma Stealer (payload le plus fréquent) XWorm, AsyncRAT, NetSupport, SectopRAT, DarkGate (RATs)
Since late March 2026, researchers have observed large-scale phishing campaigns that use fileless techniques and Lua-based loaders with low detection rates to deliver malware such as Agent Tesla, Remcos, XWorm, and Best Private LOGGER.
Our guides on fake IT support MSI backdoors, SmartRAT banking-lure cleanup, and fake tax notice XWorm infections cover similar endpoint checks.
These messages contained URLs leading to the download of a VHD file which, if clicked, ran an executable which ran Cruciferra. This malware then led to XWorm and AdaptixC2.
Since late March, 2026, we have been observing large-scale campaigns that use a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER.
Remote access trojans including DarkGate, XWorm, AsyncRAT, NetSupport, and SectopRAT are also in the ClickFix rotation, enabling hands-on-keyboard activity such as lateral movement, persistence, and data exfiltration.
XWorm8
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.