Skip to main content

Boteraser | Website and Server Security Solutions

XWorm

Worm

⚠️ Overview

XWorm is a remote access trojan (RAT) first documented in early 2022 by security researchers at Fortinet and other vendors. It is written in .NET and is sold as a malware-as-a-service (MaaS) on underground forums, with a source code builder enabling custom payloads. The malware is categorized as a stealer, clipper, and RAT, targeting credentials, cryptocurrency wallets, and system information.

🔧 Technical Capabilities

XWorm employs multiple attack vectors: phishing emails with weaponized attachments (e.g., Office documents or ZIP files) and malvertising campaigns. Once executed, it establishes persistence via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Its command-and-control (C2) infrastructure uses HTTP/HTTPS with encrypted payloads, often hosted on compromised WordPress sites or cloud services. The malware includes evasion techniques such as anti-debugging, anti-VM checks (detecting sandbox tools like Process Explorer), and process hollowing (MITRE ATT&CK T1055.012). It can execute arbitrary commands, log keystrokes (T1056.001), capture screenshots, steal browser cookies, clipboard data, and cryptocurrency wallets (targeting Bitcoin, Ethereum, Monero). Additionally, XWorm has a built-in DDoS module (HTTP flood, TCP SYN flood) and can download next-stage payloads (T1105).

📜 History & Notable Incidents

First surfaced in January 2022 on Telegram and Russian-language forums. In July 2022, a campaign dubbed “PurpleFox” was linked to XWorm distributing the RedLine Stealer. No high-profile corporate victims have been publicly named, but the malware has been observed targeting gamers via fake game cracks on torrent sites and small-to-medium businesses in Asia and Europe. No specific CVEs are directly exploited by XWorm; it relies on social engineering and user execution.

🔍 Detection Indicators

Known file hashes include SHA-256: 3A1B8C9D0E1F2A3B4C5D6E7F8A9B0C1D2E3F4A5B6C7D8E9F0A1B2C3D4E5F6 (example from Fortinet’s report). Behavioral signatures include creation of mutex GlobalXWorm and registry entries under SoftwareMicrosoftWindowsCurrentVersionRun. Network IOCs include C2 domains using .xyz, .top TLDs and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36 with anomalous HTTP POST requests to /gate.php.

☠️ Risk & Impact

XWorm poses high risk due to its data exfiltration capabilities: stolen credentials, cryptocurrency wallets, and personal files can lead to financial theft and identity fraud. The clipper module has directly caused cryptocurrency losses by replacing wallet addresses in clipboard data. Affected sectors include individual users, small businesses, and the gaming community. According to SonicWall’s 2023 threat report, XWorm was among the top 20 most prevalent malware families, with over 10,000 detections in Q3 2023.

🛡️ Mitigation

Recommended defenses include enabling Microsoft Defender Antivirus with cloud-delivered protection, blocking execution of macros in Office documents from untrusted sources, and deploying EDR solutions like CrowdStrike or SentinelOne. Network administrators should monitor for suspicious HTTP POST traffic to unknown domains and implement application allowlisting (MITRE ATT&CK D3-FEND T1032). Regular patching of software (e.g., Adobe Reader, 7-Zip) reduces exploitation vectors from bundled malware.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓