#Xworm

Modular .NET Remote Access Trojan and stealer, distributed via a publicly leaked builder

Subscribe (RSS)


#Xworm

Modular .NET RAT/stealer distributed via a leaked builder

Subscribe (RSS)


IOCs by window

Today

0

IOCs tagged #Xworm

Week

49

IOCs tagged #Xworm

Month

127

IOCs tagged #Xworm

Year

601

IOCs tagged #Xworm

Counts as of 2026-08-22. Regenerated daily.

About #Xworm

  • Type: modular .NET Remote Access Trojan and stealer, first observed around 2022. It is not open-source: cracked copies of its builder circulate on underground forums and Telegram channels, most recently a leaked v6.0 build in 2025 - the same distribution pattern that spread njRAT and AsyncRAT.
  • Abuse pattern: keylogging, screen and webcam capture, and credential / session theft from apps such as Telegram, Discord, WiFi profiles, MetaMask and FileZilla. A plugin system lets the operator load extra modules per victim, including an optional ransomware plugin. Delivered via phishing attachments, script loaders (VBS / JS / PowerShell) and trojanised software downloads.
  • Detection signals: an AES-encrypted configuration blob holding the operator's C2 host and port (no fixed default), a per-build randomised mutex to prevent multiple running instances, and heavy use of .NET obfuscators. Detection leans on behavioral and memory-based signals - reflective loading, injected .NET assemblies - rather than one static network indicator.
  • References: Malpedia.

Recent IOCs tagged #Xworm

Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/xworm.

Date Type Value Source
Aug 17, 19:15 domain trade-bitmoon.fun @skocherhan
Aug 17, 19:15 url http://trade-bitmoon.fun @skocherhan
Aug 17, 19:15 domain connect-bitmoon.fun @skocherhan
Aug 17, 19:15 url http://connect-bitmoon.fun @skocherhan
Aug 17, 19:15 domain portal-bitmoon.fun @skocherhan
Aug 17, 19:15 url http://portal-bitmoon.fun @skocherhan
Aug 17, 19:15 domain rewards-bitmoon.fun @skocherhan
Aug 17, 19:15 url http://rewards-bitmoon.fun @skocherhan
Aug 17, 19:15 domain app-bitmoon.fun @skocherhan
Aug 17, 19:15 url http://app-bitmoon.fun @skocherhan

Related tags

Tags that frequently co-occur with #Xworm.

See all tags on the Dashboard or browse the full IOC feed.

Frequently asked questions

What is XWorm?

XWorm is a modular .NET Remote Access Trojan and stealer first observed around 2022. It combines keylogging, screen and webcam capture, and credential theft from apps like Telegram, Discord and MetaMask with a plugin system that lets the operator load extra modules per victim, including an optional ransomware plugin. It is not open-source; cracked copies of its builder circulate on underground forums and Telegram channels, most recently a leaked v6.0 build in 2025.

How is XWorm typically delivered?

Most often via phishing email attachments, malicious script loaders (VBS, JS or PowerShell) and trojanised software downloads posing as cracked or pirated tools - the same loader ecosystem used to distribute njRAT and AsyncRAT. The malware does not exploit a vulnerability to install; it relies on the victim executing the dropper.

How is this list updated?

Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. Xworm-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.

What is the license? Can I use this commercially?

All TweetFeed IOC data, including this Xworm subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.

License

Xworm IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).