The XWorm Remote Access Trojan (RAT), a longstanding favorite among cybercriminals, has recently showcased a significant evolution in its attack methodology, employing an array of sophisticated stagers and loaders to evade detection and infiltrate systems.
Known for its comprehensive malicious capabilities including keylogging, remote desktop access, data exfiltration, and command execution XWorm has become a versatile tool in the arsenal of threat actors targeting sectors like the software supply chain and gaming industry.
Evolving Tactics in Cybercriminal Toolkits
Its developers continuously update the malware, enhancing its adaptability and making it a persistent challenge for cybersecurity defenses.
In a notable campaign, attackers have paired XWorm with AsyncRAT as initial-stage malware to establish footholds in victim environments, subsequently deploying ransomware payloads crafted with the leaked LockBit Black builder, highlighting tactical similarities with the notorious LockBit ransomware group.
Unlike traditional malware that often follows a predictable infection chain, XWorm’s latest iterations leverage a dynamic approach to payload delivery, cycling through an assortment of file formats and scripting languages such as PowerShell, VBS, .NET executables, JavaScript, batch scripts, and even Office macros.
This variety, often delivered through phishing campaigns via email attachments or embedded lure documents, includes file types like ZIP archives and .hta or .lnk files, designed to bypass endpoint security and sandboxing tools.

Dynamic Delivery Mechanisms
Analysis of over 1,000 samples from Malware Bazaar by the Splunk Threat Research Team (STRT) reveals common phishing lures mimicking urgent business communications such as invoices and shipping notifications to trick users into executing malicious files.
Beyond initial access, XWorm employs advanced obfuscation in its stagers and loaders, using Base64 encoding and AES encryption to conceal functionality, and tampers with Windows security features like AMSI (Antimalware Scan Interface) and ETW (Event Tracing for Windows) to suppress detection and logging.

These tactics, combined with persistence mechanisms like registry run keys, scheduled tasks, and startup folder shortcuts, ensure sustained access and potential privilege escalation within compromised systems.
XWorm’s payload further demonstrates its sophistication by conducting detailed system reconnaissance querying Windows Management Instrumentation (WMI) for antivirus software, GPU details, and video capture drivers while attempting to disable Microsoft Defender through exclusion settings.
Its ability to spread via removable media and execute backdoor commands from C2 servers, alongside process injection and DLL side-loading techniques, amplifies its threat profile.
To combat this evolving menace, STRT has developed a range of Splunk detections targeting suspicious activities such as PowerShell execution policy bypasses, renamed PowerShell instances, and unusual command-line tool executions, providing critical tools for security teams to identify and mitigate XWorm infections.
Indicators of Compromise (IOC)
| SHA256 | Description |
|---|---|
| 78b15b9b54925120b713a52a09c66674463bd689e3b01395801ef58c77651127 | Bat loader |
| 0f10d6cbaf195a7b0c9f708b7f0a225e2de29beb769bdf8d1652b682b1c4679f | Powershell script |
| 28859e4387fefb9d1f36fdf711d1b058df5effe21d726cfe6a9a285f96db1c98 | Batch script |
| 327a98bd948262a10e37e7d0692c95e30ba41ace15fe01d8e614a9813ad9d5cf | Vb script |
| 354d082858bfc5e24133854ff14bb2e89bc16e1b010b9d3372c8370d3144cdb9 | hta |
| 4a885cec3833f3872e1e38f9149936fe6bcda2181e0df163556497d42383cffa | Cmd script |
| 665e41e416954d5ff623a37c7bce17d409c11e003c29ae9ddeb25fc736e533c7 | Vb script |
| 8044220d34e77501df4a9831ac27802261ea2309f104bb49ac00301df36dee72 | Java script |
| 9db47f709898b79c9ac07e6352de9be05d6b2b91902c146272e47c17c6b8d5b2 | Powershell script |
Exclusive Webinar Alert: Harnessing Intel® Processor Innovations for Advanced API Security – Register for Free





