XWorm is a remote access trojan (RAT) first documented in early 2022 by security researchers at Fortinet and other vendors. It is written in .NET and is sold as a malware-as-a-service (MaaS) on underground forums, with a source code builder enabling custom payloads. The malware is categorized as a stealer, clipper, and RAT, targeting credentials, cryptocurrency wallets, and system information.
XWorm employs multiple attack vectors: phishing emails with weaponized attachments (e.g., Office documents or ZIP files) and malvertising campaigns. Once executed, it establishes persistence via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Its command-and-control (C2) infrastructure uses HTTP/HTTPS with encrypted payloads, often hosted on compromised WordPress sites or cloud services. The malware includes evasion techniques such as anti-debugging, anti-VM checks (detecting sandbox tools like Process Explorer), and process hollowing (MITRE ATT&CK T1055.012). It can execute arbitrary commands, log keystrokes (T1056.001), capture screenshots, steal browser cookies, clipboard data, and cryptocurrency wallets (targeting Bitcoin, Ethereum, Monero). Additionally, XWorm has a built-in DDoS module (HTTP flood, TCP SYN flood) and can download next-stage payloads (T1105).
First surfaced in January 2022 on Telegram and Russian-language forums. In July 2022, a campaign dubbed “PurpleFox” was linked to XWorm distributing the RedLine Stealer. No high-profile corporate victims have been publicly named, but the malware has been observed targeting gamers via fake game cracks on torrent sites and small-to-medium businesses in Asia and Europe. No specific CVEs are directly exploited by XWorm; it relies on social engineering and user execution.
Known file hashes include SHA-256: 3A1B8C9D0E1F2A3B4C5D6E7F8A9B0C1D2E3F4A5B6C7D8E9F0A1B2C3D4E5F6 (example from Fortinet’s report). Behavioral signatures include creation of mutex GlobalXWorm and registry entries under SoftwareMicrosoftWindowsCurrentVersionRun. Network IOCs include C2 domains using .xyz, .top TLDs and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36 with anomalous HTTP POST requests to /gate.php.
XWorm poses high risk due to its data exfiltration capabilities: stolen credentials, cryptocurrency wallets, and personal files can lead to financial theft and identity fraud. The clipper module has directly caused cryptocurrency losses by replacing wallet addresses in clipboard data. Affected sectors include individual users, small businesses, and the gaming community. According to SonicWall’s 2023 threat report, XWorm was among the top 20 most prevalent malware families, with over 10,000 detections in Q3 2023.
Recommended defenses include enabling Microsoft Defender Antivirus with cloud-delivered protection, blocking execution of macros in Office documents from untrusted sources, and deploying EDR solutions like CrowdStrike or SentinelOne. Network administrators should monitor for suspicious HTTP POST traffic to unknown domains and implement application allowlisting (MITRE ATT&CK D3-FEND T1032). Regular patching of software (e.g., Adobe Reader, 7-Zip) reduces exploitation vectors from bundled malware.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.