STATUS: ACTIVE
Source Methodology

Sources & Research Methodology

The source hierarchy and bibliography underpinning every claim on this site. Social posts and underground screenshots never override primary technical research.

TIER 1
Original security-vendor research
Primary technical analysis from established vendors.
TIER 2
Malware analysis & threat-intelligence infrastructure
Sandbox, sample, and IOC platforms.
TIER 3
CERT / government / security advisories
Official advisories and alerts.
TIER 4
High-quality cybersecurity journalism
Reputable security journalism.
TIER 5
Independent researcher observations
Researcher posts and analysis.

Core Primary Research Bibliography

PublisherTitleDateTier
CybleEvilCoder Project Selling Multiple Dangerous Tools Online2022-08-19T1
TrellixOld Loader, New Threat: Exploring XWorm RAT's Distribution and Tactics2023-07-31T1
Palo Alto NetworksXWorm persistence and XCoder/EvilCoder attribution research2023T1
ProofpointCloudflare Tunnel campaigns delivering XWorm and AsyncRAT2024T1
Microsoft Security IntelligenceXWorm malware encyclopedia entries2025-2026T1
TrellixXWorm's Evolving Infection Chain: From Predictable to Deceptive2025-09-03T1
TrellixXWorm V6: Exploring Pivotal Plugins2025T1
KPMGXWorm V6.0 threat intelligence advisory2025T1
FortiGuard LabsDeep Dive into New XWorm Campaign Utilizing Multiple-Themed Phishing Emails2026-02-10T1
ANY.RUNXWorm threat and sample intelligence2026T2
URLhausXWorm payload distribution data2022-2026T2
MalwareBazaarXWorm sample repository2026T2
ThreatFoxXWorm IOC contributions2026T2
TriageXWorm sandbox analysis2026T2
Point Wild / Lat61XWorm 7.4 infection-chain research2026-05-14T1
CloudSEKTrojanized XWorm builder incident research2024T1
Citation policy
Every major technical claim carries a citation. Footnotes show publisher, article, date, URL, and accessed date. References are never hidden. See the Changelog for update history.
XWorm Full Tech Access — 0.10 BTC — Access Granted, Network Mapped
@echophant