XWorm is a commodity Windows remote access trojan used across phishing, social-engineering, and loader-driven malware campaigns. It is commonly delivered through malicious archives, script-based droppers, fake document or tax-themed lures, ClickFix-style user-executed command chains, and multi-stage loaders implemented with JScript, VBScript, batch, PowerShell, AutoIt, Lua, Python, or .NET components. The malware is frequently deployed alongside or through other commodity malware ecosystems and loaders, including Amadey, and has also appeared in campaigns that bundle it with stealers or alternate RATs to provide redundant access.
Observed XWorm infection chains emphasize obfuscation, fileless execution, and defense evasion. Reported samples use layered script stages, runtime string reconstruction, Base64 and AES decoding, compression, AMSI bypass, event logging tampering, reflective .NET assembly loading, and in-memory execution. Delivery chains have also used process injection, including APC-based injection and shellcode loaders, to execute XWorm inside legitimate processes. Persistence mechanisms seen in XWorm-related activity include Startup-folder placement, scheduled tasks, Run-key style autoruns, and startup registration.
XWorm provides full RAT functionality consistent with sustained post-compromise control. Reported capabilities include system and host reconnaissance, encrypted command-and-control communications, user activity monitoring, keylogging, remote payload execution, and data exfiltration. Some observed operations used Telegram-based exfiltration or notification channels in addition to conventional socket-based command-and-control. Campaign reporting also links XWorm-enabled intrusions to hands-on-keyboard activity such as persistence establishment and lateral movement.
XWorm is widely used by financially motivated actors and commodity intrusion operators rather than being exclusive to a single threat group. It has appeared in broad phishing campaigns, fake government or tax-notice operations, steganography-themed delivery chains, ClickFix ecosystems, and malware distribution clusters serving multiple payload families. Targeting is opportunistic but has included organizations and users in regions such as India and Brazil, with lures themed around invoices, government notices, law-enforcement documents, and business communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2025-12 FortiGuard [[URL_5ad24528_9]] Multi-themed phishing, Equation Editor CVE-2018-0802 abuse | → XWorm RAT (XClient variant) process-hollowed into Caspol.exe → C2: alzap.ddns.com.br on a Brazilian Telefonica residential IP
1014578922 INV_PL SWB Specimen.xlam Invoice CVE-2017-11882 2026-03-24 | A Turkish-origin threat actor operating under the GitHub alias flexhere687-art ... is conducting an active XWorm V6.0 campaign using a multi-layered delivery chain.
Tearing apart a .NET crypter to extract dual XWorm RAT payloads, then decompiling the RAT to find a UEFI bootkit with BlackLotus DBX bypass, an r77 rootkit, driver infection, CVE-2026-20817 zero-day UAC bypass, and D/Invoke API evasion.
Google also observed financially motivated actors exploiting the WinRAR path-traversal flaw to distribute commodity remote access tools and information stealers such as XWorm and AsyncRAT...
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
[👽TA] TA558 (🏴): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)
The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.
Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.
The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack campaign begins with a phishing email that either contains a malicious archive or links to download one... By impersonating a reputable brand, business, or corporation, or using payment-related lures, the attacker manipulates the recipient into opening the attachment by creating a sense of urgency.
The script reconstructs the hidden command at runtime, then leverages WMI (Win32_Process and Win32_ProcessStartup) to create and execute a process silently.
Finally, we identified that this Windows Script Host (JScript) code establishes persistence...
finally uses the PS1 to load a malicious embedded payload and connects to the attacker’s Command & Control (C2) server.
The file WordDoc.bat runs and injects and executes injection code... In Batch, the %randomCharacters% like %ltc% are used by the malicious code... attackers abuse it for obfuscation to do delayed expansion.
This malware sample uses VBScript to create a batch file, WordDoc.bat.
The JavaScript, once deobfuscated, quietly pulls down a batch file from the same infrastructure.
It uses this access to allocate memory, create threads, and copy shellcode into place, all classic building blocks of process injection
APT44’s ASPX web shell leverages obfuscation techniques ... Unveiling APT28’s Advanced Obfuscated Loader and HTA Trojan ... Deobfuscating APT28’s HTA Trojan: A Deep Dive into VBE Techniques & Multi-Layer Obfuscation ... XWorm Unmasked: Weaponizing Script Obfuscation and Modern Evasion Techniques
This indicates a fileless execution technique where the payload is retrieved and executed dynamically.
It uses this access to allocate memory, create threads, and copy shellcode into place, all classic building blocks of process injection
The technique used here is Early Bird APC Queue injection. It plants code into a newly created process before that process starts running its main thread
finally decompressing it and then executing it in memory... it avoids file drops (fileless).
the first thing to do is to read the injection string from the batch file and to decode it with base64... And the second thing is to read the embedded malicious code from the batch file and to decode it, combining both Base64 and AES algorithms, and finally decompressing it
Clicking it downloads a ZIP file containing an internet shortcut, and opening it connects to a TryCloudflare subdomain.
399 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison in cleanup guidance for similar endpoint checks.
Remote access trojan used as a payload in the campaign to provide attacker control and support data theft.
A remote access trojan delivered via ClickFix campaigns to support hands-on-keyboard intrusion activity.
XWorm8
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.