XWorm is a modular Windows remote access trojan distributed under a malware-as-a-service model and active since at least mid-2022. It is commonly used in commodity cybercrime operations for persistent remote control, credential theft, keylogging, data exfiltration, and broader post-compromise activity. Reported feature sets also include cryptocurrency theft, distributed denial-of-service functionality, and in some cases ransomware deployment. XWorm is typically delivered through phishing-driven multi-stage infection chains, but it has also appeared in ClickFix social-engineering operations, steganography-themed campaigns, malicious archive and shortcut chains, shellcode-based delivery, and exploitation of vulnerabilities such as CVE-2022-30190 and CVE-2025-8088.
Observed XWorm delivery chains on Windows frequently rely on heavily obfuscated script stages using JScript, VBScript, batch, and PowerShell, as well as loaders built with LuaJIT or AutoIt. These chains emphasize defense evasion through junk-code obfuscation, runtime string reconstruction, AMSI bypass, event logging suppression, API unhooking, breakpoint neutralization, reflective loading, process injection, and fileless in-memory execution. Some campaigns establish persistence through Startup-folder artifacts, scheduled tasks, or Run-key mechanisms before loading the final .NET payload. XWorm has also been delivered by third-party malware-enablement services such as Cruciferra, which use DLL side-loading, BYOVD-assisted security-tool tampering, and ghosted or memory-resident execution to reduce detection.
The malware is widely associated with phishing campaigns impersonating trusted organizations, shipping firms, government entities, tax authorities, and business partners. It has been observed alongside other commodity malware families including AsyncRAT, Remcos, Agent Tesla, Snake Keylogger, Formbook, Lumma, DarkGate, NetSupport, SectopRAT, and zgRAT. ClickFix-related activity has placed XWorm into hands-on-keyboard intrusion workflows that can support persistence, lateral movement, and exfiltration after initial compromise. Intrusion reporting has also shown XWorm used as redundant access within broader multi-malware compromises.
XWorm primarily targets Microsoft Windows systems and is relevant across a wide range of sectors because its operators generally pursue opportunistic victimization rather than narrow vertical specialization. Documented targeting and exposure contexts include financial services, healthcare, government, travel, hospitality, education, and general enterprise environments. Its combination of MaaS availability, modularity, script-heavy loaders, and memory-resident execution has made it a recurring commodity threat in global phishing and social-engineering campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
AsyncRAT ... Exploitation of CVE-2022-30190 (Follina/MSDT “Dogwalk”) for arbitrary code execution ... Xworm ... Exploitation of the Follina vulnerability CVE-2022-30190 via malicious .docx files | Xworm is a modular, MaaS-distributed RAT first seen in July 2022... capable of ransomware deployment, DDoS, and cryptocurrency/credential theft.
Xworm ... driven by memory-only execution and abuse of the WinRAR CVE-2025-8088 exploit ... Exploitation of the WinRAR path-traversal flaw CVE-2025-8088. | Xworm is a modular, MaaS-distributed RAT first seen in July 2022... capable of ransomware deployment, DDoS, and cryptocurrency/credential theft.
2025-12 FortiGuard [[URL_5ad24528_9]] Multi-themed phishing, Equation Editor CVE-2018-0802 abuse | → XWorm RAT (XClient variant) process-hollowed into Caspol.exe → C2: alzap.ddns.com.br on a Brazilian Telefonica residential IP
1014578922 INV_PL SWB Specimen.xlam Invoice CVE-2017-11882 2026-03-24 | A Turkish-origin threat actor operating under the GitHub alias flexhere687-art ... is conducting an active XWorm V6.0 campaign using a multi-layered delivery chain.
Tearing apart a .NET crypter to extract dual XWorm RAT payloads, then decompiling the RAT to find a UEFI bootkit with BlackLotus DBX bypass, an r77 rootkit, driver infection, CVE-2026-20817 zero-day UAC bypass, and D/Invoke API evasion.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
[👽TA] TA558 (🏴): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)
The group’s other campaigns resulted in the distribution of more malware, including Async RAT and Xworm.
Like similar Storm-0900 activity, this campaign led to XWorm, a popular modular malware used by many threat actors for remote access, deployment of other malware, and data theft. XWorm uses plugins that threat actors can use to perform various tasks on compromised devices. These plugins have evolved over the years. While we have not observed it being used in attacks, the latest XWorm version includes a plugin for encrypting files, giving the malware ransomware capability.
The terminal payload is typically XWorm or AsyncRAT, both commodity RATs sold through underground forums as Malware-as-a-Service.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Instead of dropping a conventional executable, however, the malware deploys a legitimate LuaJIT or AutoIt interpreter alongside a file disguised as .ttf that actually contains encrypted Lua bytecode.
Malicious Excel spreadsheets (.xls) that drop a second .xls to trigger VBA macros
The attack chain is set in motion when a would-be victim executes an email attachment that comes in the form of a heavily obfuscated JavaScript that, when executed, establishes persistence on the victim's system and launches a second-stage loader.
Instead of dropping a conventional executable, however, the malware deploys a legitimate LuaJIT or AutoIt interpreter alongside a file disguised as .ttf that actually contains encrypted Lua bytecode.
Inside the archive sits an obfuscated JavaScript file. It hides in heavy junk code and uses control-flow flattening to defeat analysis.
Shellcode-based multi-stage delivery using steganography and reflective DLL injection
A reflective loader then maps it straight into memory, so little touches disk.
finally decompressing it and then executing it in memory... it avoids file drops (fileless).
404 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered as a final payload by the TTF Trap campaign.
A remote-access trojan delivered as a payload by Cruciferra in observed campaigns.
A modular .NET MaaS RAT capable of remote access, credential theft, crypto theft, DDoS, and ransomware deployment, often delivered through phishing and exploit chains.
A remote access trojan delivered by the TFF Trap infection chain for system control and malicious post-compromise activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.