| XWorm | 2022 | Windows | .NET | Yes | MaaS / cracked | Active 2026; fragmented post-5.6 ecosystem. |
| AsyncRAT | 2019 | Windows | .NET | Yes | Open-source origin | Also distributed via ClickFix and Cloudflare tunnels alongside XWorm (Proofpoint 2024). |
| Remcos | 2016 | Windows | C++/Native | Yes | Commercial (licensed) | Marketed as a legitimate remote administration tool but widely abused. |
| Quasar RAT | 2017 | Windows | .NET (C#) | Yes | Open-source | Open-source .NET RAT; shares runtime ecosystem with XWorm. |
| njRAT | 2012 | Windows | .NET | Yes | Commodity MaaS | Long-running .NET RAT with Arabic-language ecosystem origins. |
| NanoCore | 2013 | Windows | .NET | Yes | Cracked/leaked | Originally commercial, widely cracked; similar fragmentation pattern to XWorm. |
| DarkComet | 2008 | Windows | Delphi/Native | Yes | Discontinued | Legacy RAT; development stopped but cracked copies persist. |
| Venom RAT | 2018 | Windows | .NET | Yes | Commercial | Commodity .NET RAT in the same threat space. |
| Millenium RAT | 2020s | Windows | .NET | Yes | Commodity | Newer .NET commodity RAT. |
| Agent Tesla | 2014 | Windows | .NET | Limited | Commercial MaaS | Primarily an infostealer; often compared to XWorm's credential-theft functions. |
| Lumma Stealer | 2022 | Windows | C/C++ | Yes | MaaS | Dedicated infostealer; compared to XWorm's stealing capabilities but lacks remote-control functions. |