XWorm is a commodity .NET-based remote access trojan targeting Windows systems. It enables unauthorized remote control, including PowerShell command execution and bidirectional communication with an operator. Analyzed variants collect host information for reconnaissance and transmit it over command-and-control connections, periodically check connectivity, reconnect after disconnection, and support self-uninstallation. Its configuration can contain Base64-encoded, AES-encrypted connection settings. Observed builds also support persistence, USB-based propagation, and Windows Defender exclusions.
XWorm is delivered through phishing attachments, deceptive software-download landing pages, and multistage malware loaders. Document-based infection chains use Excel attachments, exploit-bearing RTF documents, VBScript, and image-concealed or encoded payloads. An invoice-themed phishing campaign used an LZH archive containing obfuscated JavaScript, followed by batch and PowerShell stages that decrypted and loaded XWorm in memory. XWorm has also been delivered by 2CLoader and RenEngine Loader, and attackers have attempted to deploy it through compromised ConnectWise ScreenConnect infrastructure. Other campaigns use healthcare-service impersonation or weaponized ClickOnce applications.
Multiple threat actors use XWorm rather than it being exclusive to a single operator. TA558 deployed it in the SteganoAmor campaign alongside other commodity remote-access and information-stealing malware. That campaign targeted multiple economic sectors, primarily in Latin America, with additional targeting in Russia, Romania, Turkey, and other countries. Meowsterio delivery operations have also used XWorm to maintain persistence on infected Windows machines.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-1709 (CWE-288) — Authentication Bypass Using Alternate Path or Channel. Base CVSS score of 10, indicating “Critical”.
CVE-2024-1708 (CWE-22) — Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”). Base CVSS score of 8.4, still considered “High Priority”.
The group continues to exploit the fairly old CVE-2017-11882 in its attack chain. It uses steganography, an obfuscation technique, inside the chains to spread well-known malware used in other attacks in recent years.
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw. | Xworm – Sample File name: rockstaracc.rar
Rather than using macros to execute malicious VBscript, this document uses a known vulnerability from last year (CVE-2022-30190). In summary, this vulnerability works by embedding external objects contained in a relationship file within the .docx word file. | The attack campaign (tracked by Securonix as MEME#4CHAN) was leveraging rather unusual meme-filled PowerShell code, followed by a heavily obfuscated XWorm payload to infect its victims.
Recent Xworm campaigns have leveraged multiple file formats and scripting languages, including PowerShell, VBS, HTA, and Office macro exploits such as CVE-2018-0802, to stage payloads and evade endpoint defenses. | Xworm followed closely with 183 uploads... continuing its reputation as a highly adaptable, modular RAT sold through malware-as-a-service channels.
Tearing apart a .NET crypter to extract dual XWorm RAT payloads, then decompiling the RAT to find a UEFI bootkit with BlackLotus DBX bypass, an r77 rootkit, driver infection, CVE-2026-20817 zero-day UAC bypass, and D/Invoke API evasion.
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Persistence is achieved into the machine using a malware build detected as XWorm.
NullBulge ... reportedly uses publicly available tools ... like Async RAT and Xworm before delivering LockBit payloads built using the leaked Lockbit builder.
XWorm is among the most popular RATs, used by many threat actors including TA 558.
“Seqrite/Mallory attributed a look-alike sample (Tax_Assessment.exe + libsvcs.dll > XWorm/DcRAT) to Silver Fox with medium-to-high confidence.”
Utilisation de sites gouvernementaux brésiliens compromis pour héberger des infostealers déguisés en documents fiscaux ... et des backdoors (XWORM).
Panda was so kind to share the associated dll’s with me. And indeed, they turned out to be XWorm. Associated C2s: secoundxwormm.ddns[.]net freshinxworm.ddns[.]net
33 distinct techniques documented for this family, organized by ATT&CK tactic.
« Utilisation de sites gouvernementaux brésiliens compromis pour héberger des infostealers ... et des backdoors »
A scheduled task named "MOperaChrome" is created to run the JScript file using... wscript.exe... a scheduled task with the name ("miguaned") is created to execute the JScript file.
Preceding cmd.exe, the script log_66292_ca9.ps1 is executed using powershell.exe... Additionally, the binary supported PowerShell command execution.
The windowsHide option suppresses the command window while the payload runs.
The extracted VBA script... downloads and executes a malicious powershell script.
We execute the script using, WScript.exe "PAGO-ENVIO DOCUMENTOS FACTURA 4558.js".
A scheduled task named "MOperaChrome" is created to run the JScript file using... wscript.exe... a scheduled task with the name ("miguaned") is created to execute the JScript file.
A scheduled task named "MOperaChrome" is created to run the JScript file using... wscript.exe... a scheduled task with the name ("miguaned") is created to execute the JScript file.
The first payload is loaded into memory by PowerShell and acts as a loader for the second payload. Figure 11: Process injection.
After extracting the archive, it contains a heavily obfuscated JavaScript file... The script is obfuscated by a chain of tools.
La campagna malevola sfrutta il nome e l’identità visiva del Servizio Sanitario Nazionale... Il tema sanitario ... viene utilizzato come elemento di fiducia per convincere l’utente ad avviare il file ricevuto.
The first payload is loaded into memory by PowerShell and acts as a loader for the second payload. Figure 11: Process injection.
The custom DOTNET loader... inject[s] a payload into a signed microsoft binary via process hollowing... starts a process in a suspended state... unmap[s] the memory of the target process, writes the payload... and then resume[s] the thread.
The batch script executes the PowerShell script and deletes all other files and directories being dumped... the script deletes itself and other processed files.
The function `_Expand` decrypts the data using AES... The data read from dumped files is decrypted and loaded into memory.
“[The chain] then reached InstallUtil.exe, a signed Windows utility that can be abused to run malicious code.”
The script then uses Microsoft HTML Application Host (mshta) or base64-encoded PowerShell to execute a highly obfuscated command.
858 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan observed being delivered by 2CLoader. The content does not describe its specific remote-access functionality.
The forum post advertises XWorm version 7.2 as Windows malware combining remote access, hidden VNC/RDP, credential and cryptocurrency theft, keylogging, ransomware, and USB spreading. Advertised capabilities also include webcam and screen monitoring, file and process management, command and script execution, DDoS attacks, persistence, UAC and firewall bypass, and Windows Defender deletion or exclusions. These are promotional claims; the content provides no technical analysis or evidence validating them.
A remote access trojan identified in sandbox telemetry involving infrastructure overlapping with Aurora Nocturne Night Theme's download domain. The reported execution included batch-file execution, PowerShell activity, in-memory payload loading, and persistence through a hidden scheduled task. The article does not establish that Aurora Nocturne delivered XWorm, because its historical downloaded content could not be recovered.
Remote access trojan observed among 2CLoader's delivered payloads, enabling remote control of infected Windows machines and expanding the campaign's impact beyond credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.