Friday, September 11, 2026

XWorm RAT Deploys New Stagers and Loaders to Bypass Defenses

The XWorm Remote Access Trojan (RAT), a longstanding favorite among cybercriminals, has recently showcased a significant evolution in its attack methodology, employing an array of sophisticated stagers and loaders to evade detection and infiltrate systems.

Known for its comprehensive malicious capabilities including keylogging, remote desktop access, data exfiltration, and command execution XWorm has become a versatile tool in the arsenal of threat actors targeting sectors like the software supply chain and gaming industry.

Evolving Tactics in Cybercriminal Toolkits

Its developers continuously update the malware, enhancing its adaptability and making it a persistent challenge for cybersecurity defenses.

In a notable campaign, attackers have paired XWorm with AsyncRAT as initial-stage malware to establish footholds in victim environments, subsequently deploying ransomware payloads crafted with the leaked LockBit Black builder, highlighting tactical similarities with the notorious LockBit ransomware group.

Unlike traditional malware that often follows a predictable infection chain, XWorm’s latest iterations leverage a dynamic approach to payload delivery, cycling through an assortment of file formats and scripting languages such as PowerShell, VBS, .NET executables, JavaScript, batch scripts, and even Office macros.

This variety, often delivered through phishing campaigns via email attachments or embedded lure documents, includes file types like ZIP archives and .hta or .lnk files, designed to bypass endpoint security and sandboxing tools.

XWorm RAT
Interesting XWorm Phishing File Name

Dynamic Delivery Mechanisms

Analysis of over 1,000 samples from Malware Bazaar by the Splunk Threat Research Team (STRT) reveals common phishing lures mimicking urgent business communications such as invoices and shipping notifications to trick users into executing malicious files.

Beyond initial access, XWorm employs advanced obfuscation in its stagers and loaders, using Base64 encoding and AES encryption to conceal functionality, and tampers with Windows security features like AMSI (Antimalware Scan Interface) and ETW (Event Tracing for Windows) to suppress detection and logging.

XWorm RAT
XWorm Stager Decrypt Payloads

These tactics, combined with persistence mechanisms like registry run keys, scheduled tasks, and startup folder shortcuts, ensure sustained access and potential privilege escalation within compromised systems.

XWorm’s payload further demonstrates its sophistication by conducting detailed system reconnaissance querying Windows Management Instrumentation (WMI) for antivirus software, GPU details, and video capture drivers while attempting to disable Microsoft Defender through exclusion settings.

Its ability to spread via removable media and execute backdoor commands from C2 servers, alongside process injection and DLL side-loading techniques, amplifies its threat profile.

To combat this evolving menace, STRT has developed a range of Splunk detections targeting suspicious activities such as PowerShell execution policy bypasses, renamed PowerShell instances, and unusual command-line tool executions, providing critical tools for security teams to identify and mitigate XWorm infections.

Indicators of Compromise (IOC)

SHA256Description
78b15b9b54925120b713a52a09c66674463bd689e3b01395801ef58c77651127Bat loader
0f10d6cbaf195a7b0c9f708b7f0a225e2de29beb769bdf8d1652b682b1c4679fPowershell script
28859e4387fefb9d1f36fdf711d1b058df5effe21d726cfe6a9a285f96db1c98Batch script
327a98bd948262a10e37e7d0692c95e30ba41ace15fe01d8e614a9813ad9d5cfVb script
354d082858bfc5e24133854ff14bb2e89bc16e1b010b9d3372c8370d3144cdb9hta
4a885cec3833f3872e1e38f9149936fe6bcda2181e0df163556497d42383cffaCmd script
665e41e416954d5ff623a37c7bce17d409c11e003c29ae9ddeb25fc736e533c7Vb script
8044220d34e77501df4a9831ac27802261ea2309f104bb49ac00301df36dee72Java script
9db47f709898b79c9ac07e6352de9be05d6b2b91902c146272e47c17c6b8d5b2Powershell script

Exclusive Webinar Alert: Harnessing Intel® Processor Innovations for Advanced API Security – Register for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News