When Hackers Hack Hackers
The Trojanized XWorm Builder Incident
How a malicious fake/cracked XWorm builder infected people attempting to obtain the RAT — a cybercrime lesson in attacker-on-attacker compromise.
AUTHOR: Threat Intelligence Research TeamUPDATED: 2026-10-04VERIFIED: 2026-10-04
CloudSEK documented a malicious fake/cracked XWorm builder that infected people attempting to obtain the RAT. Public reporting stated that more than 18,000 devices associated with this operation were compromised.
CYBERCRIMINAL SEEKS FREE XWORM
↓
DOWNLOADS TROJANIZED BUILDER
↓
RUNS MALICIOUS SOFTWARE
↓
BECOMES THE VICTIM
Telemetry scope
Treat the 18,000+ number specifically as telemetry relating to the trojanized-builder operation, not normal XWorm victim totals. Do not conflate these figures.
The lesson
People downloading cracked malware can themselves become victims. This is why the cracked XWorm ecosystem is a research topic in its own right — see The Cracked XWorm Ecosystem.

