STATUS: ACTIVE
When Hackers Hack Hackers

The Trojanized XWorm Builder Incident

How a malicious fake/cracked XWorm builder infected people attempting to obtain the RAT — a cybercrime lesson in attacker-on-attacker compromise.

AUTHOR: Threat Intelligence Research TeamUPDATED: 2026-10-04VERIFIED: 2026-10-04

CloudSEK documented a malicious fake/cracked XWorm builder that infected people attempting to obtain the RAT. Public reporting stated that more than 18,000 devices associated with this operation were compromised.

CYBERCRIMINAL SEEKS FREE XWORM
↓
DOWNLOADS TROJANIZED BUILDER
↓
RUNS MALICIOUS SOFTWARE
↓
BECOMES THE VICTIM
Telemetry scope
Treat the 18,000+ number specifically as telemetry relating to the trojanized-builder operation, not normal XWorm victim totals. Do not conflate these figures.
The lesson
People downloading cracked malware can themselves become victims. This is why the cracked XWorm ecosystem is a research topic in its own right — see The Cracked XWorm Ecosystem.
XWorm Full Tech Access — 0.10 BTC — Access Granted, Network Mapped
@echophant