What Happened to XWorm Developer XCoder?
The disappearance of the original XCoder identity and the emergence of XCoderTools — with the attribution caveats public research requires.
Trellix reported that development associated with XCoder continued through XWorm 5.6. During the second half of 2024, the original XCoder identity reportedly deleted its account and official support stopped.
The ecosystem then fragmented: cracked copies proliferated, modified versions appeared, and malicious copies of XWorm builders themselves began circulating. Later, an identity called XCoderTools appeared promoting XWorm 6.0.
Who is EvilCoder?
Cyble documented the "EvilCoder" malware project on August 19, 2022. Palo Alto Networks identifies XWorm as a .NET Windows RAT sold under aliases including XCoder or EvilCoder. The exact relationship between XCoder and EvilCoder has not been conclusively established.
References
- [1]Cyble, EvilCoder Project Selling Multiple Dangerous Tools Online, 2022-08-19
- [2]Trellix, Old Loader, New Threat: Exploring XWorm RAT's Distribution and Tactics, 2023-07-31
- [3]Palo Alto Networks, XWorm persistence and XCoder/EvilCoder attribution research, 2023
- [4]Trellix, XWorm's Evolving Infection Chain: From Predictable to Deceptive, 2025-09-03
- [5]Trellix, XWorm V6: Exploring Pivotal Plugins, 2025
