XWorm is a multi-purpose .NET malware family most commonly used as a remote access trojan on Windows systems. It has been observed in numerous commodity malware campaigns and is used for remote control, information theft, and follow-on malicious activity. Public reporting places it in phishing-driven intrusion chains operated by multiple cybercriminal clusters, including TA558 and DDGroup, and it has also appeared alongside other commodity malware such as AsyncRAT, Agent Tesla, Quasar RAT, NetWire, BitRAT, DcRat, and PureHVNC.
XWorm is modular and supports a broad command set for post-compromise control. Reported capabilities include remote command execution, PowerShell execution, in-memory execution of .NET payloads, file download and execution, screenshot capture, plugin retrieval, clipboard monitoring, keylogging, host reconnaissance, uninstall and update functions, and DDoS features. Some analyses also document USB spreading and simple antivirus evasion. In several campaigns, XWorm was delivered through multi-stage loaders that used obfuscation, shellcode, PowerShell, JScript, or .NET reflection, and in some cases the malware was injected into legitimate Windows processes such as RegSvcs.exe, Msbuild.exe, or notepad.exe.
Configuration data in XWorm samples has been reported as embedded in a static settings structure with encrypted fields such as host, port, keying material, and mutex-derived values. One reverse-engineering analysis found AES-ECB encryption with a key derived from the MD5 hash of the mutex. Variants observed in the wild include versions 2.2, 3.1, and 6.0.
Delivery has been strongly associated with phishing and malspam. Observed lures include invoice, shipping, quotation, reservation, and booking themes. XWorm has been distributed via malicious Microsoft Word documents, OneNote attachments, compressed archives containing scripts, JavaScript-based loaders, and weaponized PDF workflows. Some campaigns exploited CVE-2022-30190, while others abused Windows search-ms/WebDAV behavior, steganographic payload retrieval, or public file-hosting and blogging services for staging. It has also been seen in gaming-themed trojanized software distribution and in campaigns using fake updates or cracked-tool branding.
Operational use of XWorm spans broad geographic targeting and multiple sectors depending on the campaign. Reported victims have included organizations in Latin America, North America, Europe, and elsewhere, with lures aimed at hospitality, manufacturing, healthcare, finance, government, education, transportation, and general business users. XWorm is widely treated as a commodity RAT rather than a tool exclusive to a single actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw. | Xworm – Sample File name: rockstaracc.rar
Rather than using macros to execute malicious VBscript, this document uses a known vulnerability from last year (CVE-2022-30190). In summary, this vulnerability works by embedding external objects contained in a relationship file within the .docx word file. | The attack campaign (tracked by Securonix as MEME#4CHAN) was leveraging rather unusual meme-filled PowerShell code, followed by a heavily obfuscated XWorm payload to infect its victims.
Recent Xworm campaigns have leveraged multiple file formats and scripting languages, including PowerShell, VBS, HTA, and Office macro exploits such as CVE-2018-0802, to stage payloads and evade endpoint defenses. | Xworm followed closely with 183 uploads... continuing its reputation as a highly adaptable, modular RAT sold through malware-as-a-service channels.
1014578922 INV_PL SWB Specimen.xlam Invoice CVE-2017-11882 2026-03-24 | A Turkish-origin threat actor operating under the GitHub alias flexhere687-art ... is conducting an active XWorm V6.0 campaign using a multi-layered delivery chain.
Tearing apart a .NET crypter to extract dual XWorm RAT payloads, then decompiling the RAT to find a UEFI bootkit with BlackLotus DBX bypass, an r77 rootkit, driver infection, CVE-2026-20817 zero-day UAC bypass, and D/Invoke API evasion.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Final Payload: Publicly Available Trojan Families Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.
Panda was so kind to share the associated dll’s with me. And indeed, they turned out to be XWorm. Associated C2s: secoundxwormm.ddns[.]net freshinxworm.ddns[.]net
The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.
Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.
The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
USB spreader code (!), implemented in a class called USB
The RomCom and Paper Werewolf attacker groups are actively exploiting the WinRAR vulnerability to compromise systems. They distribute malicious RAR files through phishing emails.
The file might be different kinds of executables, shortcut (LNK) files, or script files such as HTML application (HTA) or Windows script file (WSF).
After deobfuscation... its core logic is designed to invoke and execute a Base64-encoded PowerShell command.
schtasks /create /sc MINUTE /mo 200 /tn EscanDissldo /F /tr “wscript.exe //b //e:jscript C:\ProgramData\MEMEMAN\UpdateEscan.js”
The downloaded file is a JavaScript script... its core logic is designed to invoke and execute a Base64-encoded PowerShell command.
Rather than using macros to execute malicious VBscript, this document uses a known vulnerability from last year (CVE-2022-30190).
This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw.
The attacker uses this encoding obfuscation technique to evade static signature detection and blacklist blocking by security gateways.
The most distinctive characteristic of TA558's recent attack campaigns... is the concealment of malicious PowerShell code or payloads within seemingly innocuous JPG images.
The first of these related files has been marked as Remcos and have the elastolut.duckdns[.]org listed as a C2
the group primarily used the archive.org data platform and the Cloudinary video platform... leveraged legitimate cloud storage services ... as payload distribution channels
the document automatically downloads and executes malicious content from a remote link... download a specified file from "ia600603.us.archive.org/.../MSI_PRO_with_b64.png"
TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.
806 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access tool delivered by Aeternum as a secondary payload in one sample.
Another malware family reportedly present in the same GitHub repository used to distribute gaming-themed malicious files.
Remote access trojan dropped by an Aeternum-linked sample; the article describes extraction of its configuration including builder version, mutex, C2 IP, port, and key.
A modular RAT offered via malware-as-a-service. Campaigns use PowerShell, VBS, HTA, and Office macro exploits for staging and evasion. Newer builds add infostealer deployment, file encryption, and DDoS capabilities alongside standard RAT functions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.