Detection Center
How to Detect XWorm
Layered detection guidance for SOC analysts and threat hunters across email, process behavior, persistence, credentials, surveillance, network, and behavioral correlation.
AUTHOR: Threat Intelligence Research TeamUPDATED: 2026-10-04VERIFIED: 2026-10-04
1. Email
- ›Suspicious invoice attachments
- ›Purchase orders / RFQs
- ›Archives, script files, LNK/URL files
- ›Unexpected Office documents
- ›ClickFix-related links
2. Process Behavior
- ›Office app → scripting engine → PowerShell → trusted binary → C2
- ›Do not rely on process name alone
- ›Correlate suspicious chains
3. Persistence
- ›Unusual Run-key modification
- ›Unexpected Startup-folder files
- ›Suspicious scheduled tasks
- ›Executables from user-writeable dirs
4. Credential Access
- ›Unusual processes accessing browser credential stores
- ›Browser cookie access
- ›Wallet-extension data access
- ›Sensitive session information
5. Surveillance
- ›Unexpected webcam access
- ›Microphone access
- ›Clipboard access
- ›Screen capture APIs
6. Network
- ›Suspicious outbound from unusual processes
- ›Dynamic-DNS C2
- ›Beacon-like repeated connections
- ›Direct TCP from injected .NET processes
7. Behavioral Correlation
- ›Combine signals across layers for high-confidence detection
High-Confidence Signal
SUSPICIOUS ATTACHMENT
↓
POWERSHELL
↓
PROCESS INJECTION
↓
AUTORUN PERSISTENCE
↓
UNKNOWN OUTBOUND C2
↓
= HIGH-CONFIDENCE MALWARE SIGNAL
Detection rules
This site references defensive YARA, Sigma, Suricata, and SIEM hunting logic. Every rule shows rule type, version, author, dates, source, false-positive considerations, and tested XWorm version. Never publish code whose purpose is to deploy or operate XWorm.
