Xworm V31 Updated
: This version was noted for including hardcoded cryptocurrency addresses. It monitors the victim's clipboard for crypto wallet strings and replaces them with the attacker's address to reroute transactions.
: Capability to monitor the clipboard and replace cryptocurrency addresses with those belonging to the attacker.
: Typically delivered via phishing emails containing malicious attachments like Excel files that exploit vulnerabilities (e.g., CVE-2018-0802) or fake invoices. Encrypted Communication
Previous versions relied on static registry run keys ( HKCU\Software\Microsoft\Windows\CurrentVersion\Run ). utilizes process doppelgänging and atom bombing . It injects code into trusted Windows processes ( svchost.exe , explorer.exe , RuntimeBroker.exe ) using randomized memory addresses every 60 seconds. This defeats signature-based detection.
The project continues to thrive following the original developer XCoder abandoning the project, with new variants including XWorm 6.0, 6.4, and 6.5 being actively distributed through phishing campaigns. XWorm is out in the open, traded on forums, complete with version updates, user support, and how-to guides, making it accessible to attackers at all skill levels. xworm v31 updated
The version numbering system for XWorm has seen multiple iterations, with variations including , v5.2 , v5.6 , v6.0 , v6.4 , v6.5 , and the subject of this analysis, v31 (which represents a major revision within the 3.x series). XWorm v31 builds upon the robust modular framework of its predecessors while introducing significant enhancements in stealth, infection chain complexity, and plugin-driven attack capabilities.
XWorm is designed for full remote control of compromised Windows systems. While introduced critical features that are still being analyzed and even "modded" by the community today, the malware's continuous updates have allowed it to outpace competitors like AsyncRAT and QuasarRAT. Key Features & Capabilities
Monitor outbound traffic for unexpected connections to known DDNS domains or uncommonly used ports. Implement strict firewall rules to block unauthorized reverse proxies.
: Features like screen recording , a keylogger , and the ability to capture screenshots. : This version was noted for including hardcoded
XWorm V3.1 infections typically follow a multi-stage execution pathway designed to minimize file-based detection.
XWorm campaigns are characterized by their diversity and adaptability in delivery methods.
: It can disable User Account Control (UAC) prompts, allowing it to run with administrative privileges without alerting the user. Service Manipulation
Are you looking to protect or personal devices ? Do you need specific YARA rules for detection, or Share public link It injects code into trusted Windows processes ( svchost
Unexpected entries in HKCU\Software\Microsoft\Windows\CurrentVersion\Run referencing unusual .exe files in the %AppData% or %Temp% directories.
The landscape of cyber threats evolves rapidly, with Remote Access Trojans (RATs) leading the charge in unauthorized system control. Among these threats, XWorm has emerged as a highly versatile and dangerous malware strain. The release of XWorm V3.1 marks a significant update in this malware's lineage, introducing enhanced evasion techniques, expanded information-stealing capabilities, and more robust command-and-control (C2) communication.
XWorm is a powerful and versatile Remote Access Trojan (RAT) that has rapidly ascended to become one of the most prevalent threats in the cyber landscape. Originally emerging in 2022, it has evolved through multiple versions—including the widely discussed and more recent iterations like v5.6 and v7.2 —solidifying its place as a top-tier "Malware-as-a-Service" (MaaS) tool. Overview of XWorm v3.1 and Beyond
The release of version 3.1 marked a significant turning point in the malware's capabilities, focusing on financial theft and stealthy distribution: