STATUS: ACTIVE
DEFENSIVE THREAT INTELLIGENCE · LIVE

XWorm: Complete RAT Malware Analysis & Threat Intelligence

Independent defensive intelligence covering XWorm versions, architecture, campaigns, command-and-control, plugins, indicators of compromise, MITRE ATT&CK techniques, detection and incident response.

xworm-intel://status
CLASSIFICATIONRemote Access Trojan
PLATFORMMicrosoft Windows
RUNTIME.NET (managed)
FIRST OBSERVED2022
ORIG. DEVELOPERXCoder / EvilCoder
DEV. STATUSDiscontinued after v5.6
POST-ORIG. ECOSYSTEMActive / fragmented
LATEST VERIFIED7.4
LAST OBSERVATION2026-10-02
CAMPAIGN STATUSActive
› Distribution: phishing · social engineering · cracked tooling · campaign loaders

Threat Dashboard

First Observed
2022
Public research (Cyble)
Type
Remote Access Trojan
Despite the name, not primarily a worm
Platform
Microsoft Windows
Desktop / server
Architecture
.NET
Managed ecosystem
Latest Verified Version
7.4
Independently verified 2026
Status
Active
Continued 2026 activity
Original Developer Alias
XCoder / EvilCoder
Online handle, not confirmed identity
Latest Observation
Oct 2026
ANY.RUN telemetry

Version and activity information continuously verified against public threat-intelligence sources.

Featured Answer — What Is XWorm?

XWorm is a Windows remote-access trojan first observed in 2022 and historically associated with the developer aliases XCoder and EvilCoder. The .NET-based malware provides unauthorized remote system control and supports credential theft, keylogging, screenshots, webcam and microphone surveillance, file management, additional payload execution and modular plugins. XWorm continues to circulate through phishing, cracked malware builders and other social-engineering campaigns, with XWorm 7.4 publicly observed during 2026.

XWorm Evolution 2022–2026

Version Registry

Latest Intelligence

2026-08-28·URLhaus
URLhaus records continued XWorm payload distribution
URLhaus records XWorm payload activity extending through 2026, with 1,188 unique payloads and 1,101 associated URLs in the research snapshot.
2026-07-01·Public reporting
xplogs22 cluster reported using XWorm against Russia/CIS targets
Public reporting in July 2026 described the xplogs22 cluster using XWorm against Russia/CIS targets. Commodity malware can be used by many unrelated operators.
2026-05-14·Point Wild / Lat61·7.4
Point Wild / Lat61 documents XWorm 7.4 multi-stage infection chain
Independent research published May 14, 2026 documented a multi-stage infection delivering XWorm 7.4.
2026-04-02·ANY.RUN·7.4
ANY.RUN analyzes XWorm 7.4 sample
Public sandbox analysis of an XWorm 7.4 sample documented persistence, scheduled-task, Startup and autorun activity with C2 communication.
2026-02-10·FortiGuard Labs·7.2
FortiGuard Labs documents XWorm 7.2 in multilingual phishing campaign
Fortinet published analysis of a business-themed phishing campaign delivering XWorm 7.2 via malicious Excel attachments exploiting CVE-2018-0802.
All news

Capability Matrix

Explore the Intelligence

Editorial Principle
This is a defensive threat-intelligence resource. It does not host XWorm binaries, builders, cracked software, source code, or operational instructions. All malicious infrastructure is defanged (e.g. malicious-example[.]com). Every claim is sourced and confidence-labeled.
XWorm Full Tech Access — 0.10 BTC — Access Granted, Network Mapped
@echophant