Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

XWorm

7
Global rank
7 infographic chevron month
Month rank
6 infographic chevron week
Week rank
0
IOCs

XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails.

RAT
Type
Ex-USSR
Origin
15 July, 2022
First seen
1 September, 2026
Last seen

How to analyze XWorm with ANY.RUN

RAT
Type
Ex-USSR
Origin
15 July, 2022
First seen
1 September, 2026
Last seen

IOCs

IP addresses
172.217.115.4
23.59.18.102
142.251.153.119
23.220.113.159
20.190.160.65
142.250.154.136
172.178.240.162
151.101.2.49
64.89.162.178
48.192.1.65
104.18.13.205
48.209.6.48
95.101.54.129
48.209.138.189
192.178.183.102
142.251.20.136
74.179.77.204
23.11.41.157
20.59.87.225
20.190.160.131
Hashes
7d757e510b1f0c4d44fd98cc0121da8ca4f44793f8583debdef300fb1dbd3715
230189617bfed9ee9f2ac01d11855b9a784d0b6481d3411693db7e1c10ade132
f1f68df4fe7f8d1febbccd47b5b14d4d5a00b008e1d5a8ecf07f874c75d35cc9
4d6541902a8234b782972e5bcfab34256178c72b3ac8db12d6e88f1c7ed4c97a
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
c52c62a7c50daf7d3f73ec16977cd4b0ea401710807d5dbe3850941dd1b73a70
d571ef33b0e707571f10bb37b99a607d6f43afe33f53d15b4395b16ef3fda665
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
498e3205bf85da0a8f8b57e292d4bd12b31d691e04039c04bedcde75d1ea7459
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
8223a912160354e05735522fdb339dc59b353ad5d1e4f4cfa94898dc348e748f
8c5fa4b29519d17593e923bc6a9a284df7a6d07fac42f897110b8fb2e0baeef5
af0edb67c2219b803c3eb6c1dee6f2d41a3fe00468a9da8be8ef5056d701abf3
97a4755fe9e653a08969f1933e3db19c712078b227bd5aa6799093abc5a0edc3
c2784e33158a807135850f7125a7eaabe472b3cfc7afb82c74f02da69ea250fe
137461792537a2e56a6475e81e2b9ad7a2bdabf1f4738fae186dca3022357349
5487ee44a4cd706d0086522e90c59c76cdf2ac68ce506fd3eae6054b9220c0cf
d673805547a0228d2f57a5ad551b8760cfcc521f38c49284ed3976e3515bca49
89d98eff14e2cf1c2314efdf392339e62d7e786f100202a7377bf7b22095a0c5
Domains
fe3cr.delivery.mp.microsoft.com
settings-win.data.microsoft.com
dl.google.com
clients1.google.com
www.microsoft.com
www.bing.com
login.live.com
keyauth.win
www.googletagmanager.com
newassets.hcaptcha.com
self.events.data.microsoft.com
sb-ssl.google.com
ocsp.digicert.com
www.google.com
nexusrules.officeapps.live.com
safebrowsing.googleapis.com
bazaar.abuse.ch
edgedl.me.gvt1.com
js.hcaptcha.com
safebrowsingohttpgateway.googleapis.com
URLs
http://clients2.google.com/time/1/current?cup2key=8:ona0-k8pheau9nh5sshbr3qgsepwxqf3nqwvn5lyl4o&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://bazaar.abuse.ch/
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://bazaar.abuse.ch/css/bootstrap.min.css
https://bazaar.abuse.ch/css/custom.css
https://bazaar.abuse.ch/css/all.min.css
https://bazaar.abuse.ch/css/jumbotron.css
https://bazaar.abuse.ch/images/malwarebazaar_logo.svg
https://bazaar.abuse.ch/js/jquery-3.5.1.min.js
https://bazaar.abuse.ch/js/bootstrap.min.js
https://bazaar.abuse.ch/js/popper.min.js
https://bazaar.abuse.ch/webfonts/fa-solid-900.woff2
https://bazaar.abuse.ch/webfonts/fa-regular-400.woff2
https://bazaar.abuse.ch/webfonts/fa-brands-400.woff2
https://bazaar.abuse.ch/favicon.ico
https://www.googletagmanager.com/gtag/js?id=g-5gqv3cj17n
https://update.googleapis.com/service/update2/json?cup2key=14:nw0nrrdsacuwfeutlwf_siffy6cuu-pq6oq0nkjui6m&cup2hreq=4aedc5e145bd787ea1657b286c111869be9c639248a7a4728d50095450e1acc0
https://bazaar.abuse.ch/browse/
Last Seen at

Recent blog posts

post image
Major Cyber Attacks in August 2026: US and EU...
watchers 1888
comments 0
post image
US Finance Under Phishing Pressure: What the...
watchers 6389
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 14505
comments 0

What is XWorm malware?

XWorm is a remote access trojan (RAT) that gives cybercriminals unauthorized access to a victim's computer. It is a modular malware, meaning that it can be customized to perform a variety of malicious tasks, such as stealing sensitive data and cryptocurrency, launching DDoS attacks, and deploying ransomware. It first came into the spotlight in July 2022 and is believed to have originated in the ex-USSR.

XWorm is sold as a malware-as-a-service (MaaS), which makes it extremely dangerous. It lowers the barrier to entry and opens hacking opportunities to more people. Since its first appearance in the global threat landscape in July 2022, XWorm has gone through several iterations. As of August 2023, the 4.2 version and the 5.0 version were the latest ones available for purchase.

Criminals use multi-stage attacks to deploy XWorm on victims’ computers. For example, an attack might start with a phishing email that contains a malicious Word document attachment. When the document is opened, it will load an .rtf file from an external link. This file will contain an Excel spreadsheet with macros that will execute a PowerShell script, which will then download XWorm onto the computer.

Technical details of the XWorm malicious software

XWorm is developed with the .NET Framework, which makes it a significant threat to Windows systems. The malware is also configurable, offering a wide range of tools for manipulating the infected machine.

Here are some of XWorm’s key capabilities:

  • Encrypted connection: XWorm is capable of maintaining a secure connection with its C&C server, even during poor network conditions.
  • Information gathering: The malware can collect a wide range of information from the infected computer, including credit card numbers, browsing history, bookmarks, downloads, as well as Firefox and Chromium passwords and cookies.
  • Account hijacking: XWorm can hack Discord, Telegram, and MetaMask accounts, as well as get hold of WiFi keys and product keys.
  • User activity tracking: The malware enables attackers to monitor the victim’s activities on their computer by logging their keystrokes, automatically saving webcam images, listening to their microphone, scanning their network connections, and viewing opened windows.
  • Clipboard access: XWorm can retrieve the information that has been copied to the clipboard and replace victims’ crypto wallet credentials with those of the attacker.
  • File management: It can gain control of a computer’s file system to transfer sensitive documents and content to its C2 or download additional malware and run it.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

In order to bypass User Account Control (UAC), XWorm attempts to get administrator permissions on the infected computer. This allows it to make changes to the system without requiring user consent. To ensure persistence, the malware adds itself to the list of programs that run automatically when the computer starts up by editing the registry.

It is also polymorphic, meaning that the malware’s code regularly transforms itself to throw detection software off course. Although XWorm has a built-in functionality to terminate its execution once it senses that it is launched in a virtualized environment, the ANY.RUN sandbox has no problem identifying the malware.

XWorm’s configuration

XWorm’s configuration

Execution process of XWorm

The malicious behavior of XWorm can be easily uncovered by uploading it to the ANY.RUN sandbox. Here is a sample of this malware on the platform.

Immediately upon execution, XWorm drops an executable file into the Startup directory (“C:\Users\admin/AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\XWorm.exe”) and into the Roaming directory (“C:\Users\admin/AppData\Roaming\XWorm.exe”).

XWorm’s process graph

XWorm’s process graph

For the latter directory, a persistent service is created using the Task Scheduler. Malware checks for an external IP, which we can bypass with ANY.RUN’s Residential Proxy feature. After this, XWorm starts sending beacons to the C&C server, waiting for commands to execute.

Read a detailed analysis of XWorm in our blog.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Distribution methods of the XWorm malware

As with most malware families, email phishing campaigns serve as XWorm’s main gateway to victims’ computers. The attack begins with an email containing an attachment. By exploiting different social engineering techniques, threat actors can persuade a user to download the attached file and open it.

Analysts have observed several file formats used by attackers, including .rtf, .lnk, and .pdf. In most cases, the email attachment itself does not contain any macros and is used primarily to kick off a chain reaction that involves downloading several other files, executing PowerShell scripts, and finally delivering the payload.

Such attacks can be facilitated by specialized tools, such as Freeze[.]rs and SYK Crypter, which are equipped with advanced capabilities for circumventing defense systems to drop a variety of malware families including Remcos RAT, njRAT, and RedLine Stealer.

One of the most recent XWorm attacks targeted businesses in Germany. It involved sending a .docx document to victims with a name that suggested it contained hotel reservation information. Instead of using macros, the file exploited the Follina vulnerability (CVE-2022-30190) to run external malicious files and a PowerShell script, which eventually dropped XWorm.

Conclusion

XWorm retains considerable staying power due to the consistent updates and wide availability, making it a top concern for organizations around the world. To protect your system from this threat, you need to have a stricter approach towards handling any links or files arriving in your inbox from unknown senders.

Instead of downloading documents and opening URLs, you can first analyze them in the ANY.RUN sandbox to quickly understand whether the file is malicious or not. ANY.RUN also provides you with a detailed report about the malware, such as its IOCs and TTPs. This information can be used to protect your organization from future attacks.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

ClickFix screenshot
ClickFix is a sophisticated social engineering technique that tricks users into manually executing malicious commands on their devices. It masquerades as a "quick fix" for fake technical issues, CAPTCHA verifications, or error messages, often hijacking the clipboard to paste harmful PowerShell or terminal commands. This user-assisted approach helps it bypass traditional security controls, leading to infostealers like Lumma Stealer, RATs, and other malware.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More
StrelaStealer screenshot
StrelaStealer
strela
StrelaStealer is a malware that targets email clients to steal login credentials, sending them back to the attacker’s command-and-control server. Since its emergence in 2022, it has been involved in numerous large-scale email campaigns, primarily affecting organizations in the EU and U.S. The malware’s tactics continue to evolve, with attackers frequently changing attachment file formats and updating the DLL payload to evade detection.
Read More
UpCrypter screenshot
UpCrypter
upcrypter
UpCrypter is a sophisticated malware loader that functions as a delivery mechanism for remote access tools. Distributed through global phishing campaigns targeting Windows systems, this actively maintained tool serves as the central framework for deploying various RATs including PureHVNC, DCRat, and Babylon RAT, enabling attackers to establish persistent remote control over compromised systems.
Read More
Octo screenshot
Octo
octo coper
Octo malware, also known as ExobotCompact or Coper, is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot. It poses a significant threat to financial institutions, mobile users, and enterprise networks.
Read More