#XWorm
Hey guys time to uncover a trojanized XWorm Rat builder 💞
January 27, 2025 at 2:35 PM
Falso sito del Servizio Sanitario Nazionale distribuisce StreamRat su Android e XWorm su Windows
#infosec
cert-agid.gov.it/news/falso-s...
Falso sito del Servizio Sanitario Nazionale distribuisce StreamRat su Android e XWorm su Windows
Il CERT-AGID ha analizzato una campagna malevola che sfrutta il nome e l'identità visiva del Servizio Sanitario Nazionale per distribuire malware sia su dispositivi Android sia su sistemi Windows. Il...
cert-agid.gov.it
September 24, 2026 at 8:09 PM
Falso sito del Servizio Sanitario Nazionale distribuisce StreamRat su Android e XWorm su Windows
#infosec
https://cert-agid.gov.it/news/falso-sito-del-servizio-sanitario-nazionale-distribuisce-streamrat-su-android-e-xworm-su-windows/
Falso sito del Servizio Sanitario Nazionale distribuisce StreamRat su Android e XWorm su Windows
cert-agid.gov.it
September 24, 2026 at 8:10 PM
booking .com 🏨 themed #ClickFix campaign using a fake cookie 🍪 banner, downloading a JavaScript file dropping XWorm 🔥

JS:
📜 bazaar.abuse.ch/sample/01a2f...

EXE:
📄 bazaar.abuse.ch/sample/6ccf4...

URLs:
🌐 urlhaus.abuse.ch/host/185.7.2...

XWorm botnet C2s:
📡185.7.214.108:4411
📡185.7.214.54:4411
February 24, 2025 at 11:55 AM
New versions of the XWorm backdoor are being distributed in phishing campaigns after the original developer, XCoder, abandoned the project last year.
XWorm malware resurfaces with ransomware module, over 35 plugins
New versions of the XWorm backdoor are being distributed in phishing campaigns after the original developer, XCoder, abandoned the project last year.
www.bleepingcomputer.com
October 6, 2025 at 11:42 AM
🚨 IOC Alert: XWorm Command-and-Control Infrastructure

darkwebinformer.com/ioc-alert-xw...
IOC Alert: XWorm Command-and-Control Infrastructure
IOC Alert: XWorm Command-and-Control Infrastructure
darkwebinformer.com
September 3, 2025 at 6:00 PM
Fake SSN Site Delivers StreamRat and XWorm with Platform-Specific Payloads
Fake SSN Site Delivers StreamRat and XWorm with Platform-Specific Payloads
CERT-AGID analyzed a campaign abusing the Italian National Health Service brand to distribute full-featured RATs on Android and Windows. The payloads use dynamic, C2-driven HTML overlays and fileless execution to evade traditional detection.
deafnews.it
September 24, 2026 at 1:09 PM
XWorm 6.0 Returns with 35+ Plugins and Enhanced Data Theft Capabilities
XWorm 6.0 Returns with 35+ Plugins and Enhanced Data Theft Capabilities
thehackernews.com
October 7, 2025 at 12:16 PM
🚨Alleged leak of XWorm RAT V5.7

Blur: Link to the release
April 2, 2025 at 3:58 PM
Want More XWorm? https://isc.sans.edu/diary/32766
March 4, 2026 at 9:51 AM
A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access trojan to gain network access that could lead to ransomware attacks.
Initial access hackers switch to Tsundere Bot for ransomware attacks
A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access trojan to gain network access that could lead to ransomware attacks.
www.bleepingcomputer.com
January 28, 2026 at 11:29 PM
High-value technical breakdown of a sophisticated attack chain. XWorm malware uses steganography to hide malicious DLLs inside images, bypassing security tools through a multi-stage attack starting with phishing PDFs and registry modifications. thehackernews.com/20...
Steganography Explained: How XWorm Hides Inside Images
Cybercriminals use steganography to hide malware inside images, evading security tools and enabling stealthy attacks. Learn how to detect and prevent
thehackernews.com
March 12, 2025 at 4:05 AM
Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT thehackernews.com/2026/03/mult...
Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT
VOID#GEIST malware campaign delivers XWorm, AsyncRAT, and Xeno RAT using batch scripts, Python loaders, and explorer.exe injection.
thehackernews.com
March 8, 2026 at 11:35 AM
New XWorm V6 Variant’s With Anti-Analysis Capabilities Attacking Windows Users in The Wild
New XWorm V6 Variant’s With Anti-Analysis Capabilities Attacking Windows Users in The Wild
XWorm V6.0 uses obfuscated VBScript, anti-analysis, and stealth techniques to evade detection and infect Windows systems via social lures.
cybersecuritynews.com
July 30, 2025 at 7:23 PM
New XWorm 7.1 and Remcos RAT campaigns are abusing trusted #Windows utilities and memory-based execution to evade detection. The campaign also exploits a #WinRAR vulnerability to gain initial access.

Read: hackread.com/xworm-7-1-re...

#CyberSecurity #Malware #XWorm #RemcosRAT
XWorm 7.1 and Remcos RAT Attacks Abuse Windows Tools to Evade Detection
New XWorm 7.1 and Remcos RAT campaigns abuse trusted Windows tools to evade detection. The attacks exploit a WinRAR flaw and use process hollowing to spy on victims.
hackread.com
March 16, 2026 at 11:29 AM
-New JSCEAL malware
-XWorm V6 is out
-Gunra ransomware gets a Linux variant
-Avast releases FunkSec ransomware decrypter
-Google P0 changes reporting rules
-Train maker sues security researchers
-Sploitlight macOS TCC vulnerability
-Sex toy leaks user emails
-Gen. Haugh joins VC space
July 30, 2025 at 8:30 AM
A trojanized XWorm RAT builder, spread via GitHub & Telegram, infected nearly 18,500 computers. The malware stole data and granted remote access. A kill switch was deployed, but some systems remain compromised.#XWormRATAttack
January 24, 2025 at 5:06 PM
AsyncRAT uses Python & TryCloudflare for stealth. Phishing delivers a ZIP > URL > LNK > PowerShell > JavaScript, downloading AsyncRAT, Venom RAT, and XWorm. Legitimate services are abused for obfuscation.#AsyncRATThreat
February 5, 2025 at 11:08 AM
Watch out as hackers are sending fake invoices in emails with malicious Office files to install the XWorm RAT on #Windows systems in a new attack.

Read: hackread.com/hackers-fake...

#CyberSecurity #Malware #Phishing #XWorm #InfoSec
Hackers Use Fake Invoices to Spread XWorm RAT via Office Files
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
September 27, 2025 at 11:03 AM
Two new posts with #pcap, #malware, other files and #indicators for #XWorm (Tuesday, 2026-09-08) and #AMOS #Stealer (Thursday, 2026-09-10).

www.malware-traffic-analysis.net/2026/index.h...
September 10, 2026 at 10:19 PM
Steganography Explained: How XWorm Hides Inside Images #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
March 11, 2025 at 8:33 PM
-Americans lost $388m to crypto ATMs
-FlowerStorm PhaaS adds VM-based obfuscation
-APT37 poses as the police
-Twill Typhoon's FDMTP backdoor
-New TencShell attacks
-Sandworm and Leek Likho activity still going
-UK sanctions Russian disinfo firms
-Malware reports on Gremlin Stealer, Vidar, XWorm
May 18, 2026 at 7:37 AM
Hackers Use XWorm RAT to Exploit Script Kiddies, Pwning 18,000 Devices https://buff.ly/4jxf8So
Hackers Use XWorm RAT to Exploit Script Kiddies, Pwning 18,000 Devices
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
buff.ly
January 25, 2025 at 11:42 AM
📢⚠️ Hackers are exploiting an old Excel vulnerability to spread XWorm 7.2 malware hidden in JPEG files disguised as invoices. The attack steals passwords and Wi-Fi keys and grants remote access to infected PCs.

Read: hackread.com/hackers-exce...

#CyberSecurity #Malware #Phishing #XWorm #Microsoft
Hackers Use Excel Exploit to Hide XWorm 7.2 in JPEG Files, Hijack PCs
A new phishing campaign is spreading XWorm 7.2 via malicious Excel files, hiding malware in Windows processes to steal passwords and Wi-Fi keys.
hackread.com
February 23, 2026 at 12:08 PM