STATUS: ACTIVE
Developer Attribution

What Happened to XWorm Developer XCoder?

The disappearance of the original XCoder identity and the emergence of XCoderTools — with the attribution caveats public research requires.

AUTHOR: Threat Intelligence Research TeamUPDATED: 2026-10-04VERIFIED: 2026-10-04

Trellix reported that development associated with XCoder continued through XWorm 5.6. During the second half of 2024, the original XCoder identity reportedly deleted its account and official support stopped.

The ecosystem then fragmented: cracked copies proliferated, modified versions appeared, and malicious copies of XWorm builders themselves began circulating. Later, an identity called XCoderTools appeared promoting XWorm 6.0.

Attribution caveat
The relationship between XCoderTools and the original XCoder identity has not been conclusively established in public research. We do not state they are the same. This distinction is important for credibility.
XCODER (5.6)
↓
ACCOUNT DELETED (H2 2024)
↓
ECOSYSTEM FRAGMENTED
↓
CRACKED / MODIFIED BUILDS
↓
XCODERTOOLS (6.0)

Who is EvilCoder?

Cyble documented the "EvilCoder" malware project on August 19, 2022. Palo Alto Networks identifies XWorm as a .NET Windows RAT sold under aliases including XCoder or EvilCoder. The exact relationship between XCoder and EvilCoder has not been conclusively established.

Terminology
These are developer aliases / online handles / malware-development identities — not confirmed real-world persons.

References

  1. [1]Cyble, EvilCoder Project Selling Multiple Dangerous Tools Online, 2022-08-19
  2. [2]Trellix, Old Loader, New Threat: Exploring XWorm RAT's Distribution and Tactics, 2023-07-31
  3. [3]Palo Alto Networks, XWorm persistence and XCoder/EvilCoder attribution research, 2023
  4. [4]Trellix, XWorm's Evolving Infection Chain: From Predictable to Deceptive, 2025-09-03
  5. [5]Trellix, XWorm V6: Exploring Pivotal Plugins, 2025
XWorm Full Tech Access — 0.10 BTC — Access Granted, Network Mapped
@echophant