Command & Control
How XWorm Command-and-Control Works
A safe architectural explanation of XWorm C2 communications across versions and campaigns.
AUTHOR: Threat Intelligence Research TeamUPDATED: 2026-10-04VERIFIED: 2026-10-04
COMPROMISED ENDPOINT
↓
XWORM CLIENT
↓
ENCRYPTED SESSION
↓
ATTACKER C2
↓
REMOTE TASKING / COLLECTION
Research has documented direct socket/TCP-based C2 architectures across versions. Different campaigns may use IP addresses, domains, dynamic DNS, temporary infrastructure, abused cloud infrastructure, or loaders that contact separate staging infrastructure.
Some trojanized XWorm-related builds have also incorporated Telegram-based communications. However, core XWorm campaigns frequently use direct C2 infrastructure; Telegram is particularly notable in modified/trojanized ecosystems.
Do not overgeneralize
Do not incorrectly claim "XWorm normally uses Telegram as its primary C2." Core XWorm campaigns frequently use direct C2 infrastructure. Telegram is a legitimate communications platform that can be abused by criminal operators. See XWorm and Telegram.
Cloudflare tunnel abuse
Proofpoint documented campaigns in 2024 using Cloudflare tunnels in attack chains distributing XWorm and AsyncRAT. Temporary legitimate cloud infrastructure presents challenges: infrastructure can be rapidly created, domains/IPs change, static blocklists become less useful. Cloudflare is a legitimate provider whose services can be abused by threat actors — Cloudflare is not associated with development of XWorm.
References
- [1]Trellix, Old Loader, New Threat: Exploring XWorm RAT's Distribution and Tactics, 2023-07-31
- [2]Proofpoint, Cloudflare Tunnel campaigns delivering XWorm and AsyncRAT, 2024
- [3]Trellix, XWorm's Evolving Infection Chain: From Predictable to Deceptive, 2025-09-03
- [4]Trellix, XWorm V6: Exploring Pivotal Plugins, 2025
- [5]FortiGuard Labs, Deep Dive into New XWorm Campaign Utilizing Multiple-Themed Phishing Emails, 2026-02-10

