SYMBOLCOMMON_NAMEaka. SYNONYMS
win.xworm (Back to overview)

XWorm

Actor(s): Hive0137


Malware with wide range of capabilities ranging from RAT to ransomware.

References
2026-02-17 ⋅ ANY.RUN ⋅ ANY.RUN
LATAM Businesses Hit by XWorm via Fake Financial Receipts: Full Campaign Analysis
XWorm
2026-01-28 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team
Can’t stop, won’t stop: TA584 innovates initial access
XWorm TA584
2026-01-13 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update July to December 2025
Coper FluBot Joker Aisuru Mirai AsyncRAT BianLian Cobalt Strike DCRat Havoc Latrodectus PureLogs Stealer Quasar RAT Remcos Rhadamanthys Sliver ValleyRAT Venom RAT Vidar XWorm
2025-12-19 ⋅ cyble ⋅ Cyble
Stealth in Layers: Unmasking the Loader used in Targeted Email Campaigns
DCRat Katz Stealer PhantomVAI PureLogs Stealer Remcos XWorm
2025-12-01 ⋅ LinkedIn (Microsoft) ⋅ Microsoft Threat Intelligence
Post about Phishing Campaign pushing XWorm
XWorm TA584
2025-10-02 ⋅ Trellix ⋅ Niranjan Hegde, Sijo Jacob
XWorm V6: Exploring Pivotal Plugins
XWorm
2025-09-25 ⋅ Logpoint ⋅ Akanksha Giri, Anish Bogati
XWorm RAT analysis: Steal,
 persist & control
XWorm
2025-09-12 ⋅ Medium (@zyadlzyatsoc) ⋅ Zyad Elzyat
XWorm Malware Analysis: SOC & IR Perspective on Persistence, C2, and Anti-Analysis Tactics
XWorm
2025-08-20 ⋅ Kroll ⋅ Marc Messer, Otavio Passos, Ryan Hicks
XWORM Returns to Haunt Systems with Ghost Crypt
XWorm
2025-07-28 ⋅ Github (Yavuzhanzgen) ⋅ Yavuzhan Özgen
XWorm V3.1 Malware Technical Analysis Report
XWorm
2025-07-14 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update January to June 2025
Coper FluBot Hook Joker Mirai AsyncRAT BianLian BumbleBee Chaos Cobalt Strike DanaBot DCRat Havoc Latrodectus NjRAT Quasar RAT RedLine Stealer Remcos Rhadamanthys Sliver ValleyRAT WarmCookie XWorm
2025-07-06 ⋅ MalwareTrace ⋅ Jared G.
XWorm Part 2 - From Downloader to Config Extraction
XWorm
2025-07-03 ⋅ MalwareTrace ⋅ Jared G.
XWorm Part 1 - Unraveling a Steganography-Based Downloader
XWorm
2025-06-05 ⋅ Hunt.io ⋅ Hunt.io
Abusing Paste.ee to Deploy XWorm and AsyncRAT Across Global C2 Infrastructure
AsyncRAT XWorm
2025-04-17 ⋅ Trustwave ⋅ Dawid Nesterowicz, Pawel Knapczyk
Proton66 Part 2: Compromised WordPress Pages and Malware Campaigns
StrelaStealer TargetCompany XWorm
2025-03-06 ⋅ Medium SarvivaMalwareAnalyst ⋅ sarviya
XWorm Attack Chain: Leveraging Steganography from Phishing Email to Keylogging via C2 Communication
XWorm
2025-02-12 ⋅ cyber.wtf blog ⋅ Hendrik Eckardt, Leonard Rapp
Unpacking Pyarmor v8+ scripts
AsyncRAT DCRat XWorm
2025-02-12 ⋅ Red Canary ⋅ Phil Hagen, Tony Lambert
Defying tunneling: A Wicked approach to detecting malicious network traffic
AsyncRAT DCRat NjRAT XWorm
2024-12-06 ⋅ Github (VenzoV) ⋅ VenzoV
Shellcode Loader Delivering XWorm
XWorm
2024-11-28 ⋅ Hunt.io ⋅ Hunt.io
Uncovering Threat Actor Tactics: How Open Directories Provide Insight into XWorm Delivery Strategies
XWorm
2024-11-18 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team, Selena Larson, Tommy Madjar
Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape
AsyncRAT Brute Ratel C4 DanaBot DarkGate Latrodectus Lumma Stealer NetSupportManager RAT XWorm
2024-09-12 ⋅ kienmanowar Blog ⋅ m4n0w4r, Tran Trung Kien
[QuickNote] The Xworm malware is being spread through a phishing email
XWorm
2024-07-26 ⋅ SecurityIntelligence ⋅ Golo Mühr, Joe Fasulo
Hive0137 and AI-supplemented malware distribution
WarmCookie XWorm Hive0137
2024-07-16 ⋅ Sentinel LABS ⋅ Jim Walter
NullBulge | Threat Actor Masquerades as Hacktivist Group Rebelling Against AI
AsyncRAT LockBit XWorm Nullbulge
2024-05-14 ⋅ Check Point Research ⋅ Antonis Terefos, Tera0017
Foxit PDF “Flawed Design” Exploitation
Rafel RAT Agent Tesla AsyncRAT DCRat DONOT Nanocore RAT NjRAT Pony Remcos Venom RAT XWorm
2024-04-15 ⋅ Positive Technologies ⋅ Aleksandr Badaev, Kseniya Naumova
SteganoAmor campaign: TA558 mass-attacking companies and public institutions all around the world
LokiBot 404 Keylogger Agent Tesla CloudEyE Formbook Remcos XWorm
2024-03-27 ⋅ Twitter (@embee_research) ⋅ Embee_research
Uncovering Malicious Infrastructure with DNS Pivoting
LokiBot XWorm
2024-03-11 ⋅ YouTube (Embee Research) ⋅ Embee_research
Xworm Script Analysis and Deobfuscation
XWorm
2024-02-22 ⋅ Medium b.magnezi ⋅ 0xMrMagnezi
Malware Analysis - XWorm
XWorm
2024-02-01 ⋅ Hunt.io ⋅ Hunt.io
The Accidental Malware Repository: Hunting & Collecting Malware Via Open Directories (Part 1)
XWorm
2024-02-01 ⋅ YouTube (Embee Research) ⋅ Embee_research
Xworm Malware Analysis - Unravelling Multi-stage Malware with CyberChef and DnSpy
XWorm
2023-11-21 ⋅ ANY.RUN ⋅ Igal Lytzki
XWorm Malware: Exploring C&C Communication
XWorm
2023-10-24 ⋅ CERT.PL ⋅ Jarosław Jedynak
Malware stories: Deworming the XWorm
XWorm
2023-09-08 ⋅ Gi7w0rm
Uncovering DDGroup — A long-time threat actor
AsyncRAT Ave Maria BitRAT DBatLoader NetWire RC Quasar RAT XWorm
2023-08-24 ⋅ ANY.RUN ⋅ Electron, glebyao, kinoshi
XWorm: Technical Analysis of a New Malware Version
XWorm
2023-08-23 ⋅ Twitter (@embee_research) ⋅ Embee_research, Huntress Labs
Extracting Xworm from Bloated Golang Executable
XWorm
2023-08-01 ⋅ Palo Alto Networks Unit 42 ⋅ Lior Rochberger
NodeStealer 2.0 – The Python Version: Stealing Facebook Business Accounts
BitRAT NodeStealer XWorm
2023-05-12 ⋅ Securonix ⋅ Den Iyzvyk, Oleg Kolesnikov, Tim Peck
Ongoing MEME#4CHAN Attack/Phishing Campaign uses Meme-Filled Code to Drop XWorm Payloads
XWorm
2023-04-07 ⋅ Elastic ⋅ Salim Bitam
Attack chain leads to XWORM and AGENTTESLA
Agent Tesla XWorm
2023-03-30 ⋅ loginsoft ⋅ Saharsh Agrawal
From Innocence to Malice: The OneNote Malware Campaign Uncovered
Agent Tesla AsyncRAT DOUBLEBACK Emotet Formbook IcedID NetWire RC QakBot Quasar RAT RedLine Stealer XWorm
2023-02-02 ⋅ YouTube (Embee Research) ⋅ Embee_research
Xworm Loader Analysis - Decoding Malware Scripts and Extracting C2's with DnSpy and CyberChef
XWorm
2022-08-19 ⋅ cyble ⋅ Cyble
EvilCoder Project Selling Multiple Dangerous Tools Online
XWorm
Yara Rules
[TLP:WHITE] win_xworm_w0 (20240730 | Detects win.xworm.)
rule win_xworm_w0 {

    meta:
        author = "jeFF0Falltrades"
        date = "2024-07-30"
        version = "1"
        description = "Detects win.xworm."
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xworm"
        malpedia_rule_date = "20240730"
        malpedia_hash = ""
        malpedia_version = "20240730"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    strings:
        $str_xworm = "xworm" wide ascii nocase
        $str_xwormmm = "Xwormmm" wide ascii
        $str_xclient = "XClient" wide ascii
        $str_xlogger = "XLogger" wide ascii
        $str_xchat = "Xchat" wide ascii
        $str_default_log = "\\Log.tmp" wide ascii
        $str_create_proc = "/create /f /RL HIGHEST /sc minute /mo 1 /t" wide ascii 
        $str_ddos_start = "StartDDos" wide ascii 
        $str_ddos_stop = "StopDDos" wide ascii
        $str_timeout = "timeout 3 > NUL" wide ascii
        $byte_md5_hash = { 7e [3] 04 28 [3] 06 6f }
        $patt_config = { 72 [3] 70 80 [3] 04 }

    condition:
        5 of them and #patt_config >= 5
 }
Download all Yara Rules