Researchers reported that XWorm re-emerged with the release of XWorm V6 after the malware had been widely considered abandoned, and that its latest campaigns used a modular plugin architecture to expand capabilities on infected Windows systems. In one observed chain, a malicious JavaScript file launched PowerShell, disabled AMSI, deployed an injector DLL, and injected the XWorm client into RegSvcs.exe, after which the malware contacted a command-and-control server at 94.159.113.64:4411. The malware stored plugins in the registry and retrieved them on demand to enable remote desktop control, shell access, credential theft, browser data theft, file management, persistence, and ransomware activity; researchers also linked some browser-theft components to public proof-of-concept code designed to bypass Chrome v20 protections.
Separate reporting found that threat actors were circulating a trojanized XWorm builder, underscoring infighting in the cybercrime ecosystem and showing that some operators and would-be customers were themselves being infected. Trellix likewise observed cracked and modified XWorm V6 builders, including leaked V6.4 variants containing Rootkit.dll and ResetSurvival.dll, and said some builders and operators had been compromised by XWorm malware. The malware’s persistence methods included logon scripts, Run keys, and abuse of ResetConfig.xml, while operators also deployed payloads such as DarkCloud Stealer, Remcos RAT, and other stealers; its ransomware plugin used AES-CBC, dropped a ransom note, changed the victim’s wallpaper, and showed code overlap with NoCry ransomware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A Hackforums post from the account XCoderTools announced XWorm V6.0 on June 4, 2025, claiming the new version fixed the prior remote code execution vulnerability affecting V5.6 and earlier.
After the June 2025 release of XWorm V6.0, Trellix observed a surge of related samples being uploaded to VirusTotal, indicating renewed activity around the malware family.
After releasing XWorm V5.6, XWorm developer XCoder disappeared in the latter half of 2024, contributing to the belief that the malware project had been abandoned.
XWorm was first observed in 2022 as a modular malware family built around a core client with multiple plugins.
Following XWorm's apparent abandonment, threat actors began distributing cracked or modified XWorm V5.6 versions, including trojanized builders.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.