XWorm: Complete RAT Malware Analysis & Threat Intelligence
Independent defensive intelligence covering XWorm versions, architecture, campaigns, command-and-control, plugins, indicators of compromise, MITRE ATT&CK techniques, detection and incident response.
Threat Dashboard
Version and activity information continuously verified against public threat-intelligence sources.
Featured Answer — What Is XWorm?
XWorm is a Windows remote-access trojan first observed in 2022 and historically associated with the developer aliases XCoder and EvilCoder. The .NET-based malware provides unauthorized remote system control and supports credential theft, keylogging, screenshots, webcam and microphone surveillance, file management, additional payload execution and modular plugins. XWorm continues to circulate through phishing, cracked malware builders and other social-engineering campaigns, with XWorm 7.4 publicly observed during 2026.
XWorm Evolution 2022–2026
Version Registry
Latest Intelligence
Capability Matrix
- ›Keylogging
- ›Screenshots
- ›Webcam monitoring
- ›Microphone / audio access
- ›Browser credentials
- ›Stored passwords
- ›Cookies / session data
- ›Autofill information
- ›Remote shell
- ›Process interaction
- ›File management
- ›Upload / download
- ›Username
- ›Computer name
- ›OS
- ›Architecture
- ›Clipboard monitoring
- ›Cryptocurrency-address replacement
- ›Browser-wallet exposure
- ›File encryption / ransomware-like capability (some plugins)
- ›Disruptive operations
- ›DDoS functionality (some plugins)
- ›Additional malware deployment

