#Xworm
Modular .NET Remote Access Trojan and stealer, distributed via a publicly leaked builder
IOCs by window
0
IOCs tagged #Xworm
49
IOCs tagged #Xworm
127
IOCs tagged #Xworm
601
IOCs tagged #Xworm
Counts as of 2026-08-22. Regenerated daily.
About #Xworm
- Type: modular .NET Remote Access Trojan and stealer, first observed around 2022. It is not open-source: cracked copies of its builder circulate on underground forums and Telegram channels, most recently a leaked v6.0 build in 2025 - the same distribution pattern that spread njRAT and AsyncRAT.
- Abuse pattern: keylogging, screen and webcam capture, and credential / session theft from apps such as Telegram, Discord, WiFi profiles, MetaMask and FileZilla. A plugin system lets the operator load extra modules per victim, including an optional ransomware plugin. Delivered via phishing attachments, script loaders (VBS / JS / PowerShell) and trojanised software downloads.
- Detection signals: an AES-encrypted configuration blob holding the operator's C2 host and port (no fixed default), a per-build randomised mutex to prevent multiple running instances, and heavy use of .NET obfuscators. Detection leans on behavioral and memory-based signals - reflective loading, injected .NET assemblies - rather than one static network indicator.
- References: Malpedia.
Recent IOCs tagged #Xworm
Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/xworm.
| Date | Type | Value | Source |
|---|---|---|---|
| domain | |||
| url | |||
| domain | |||
| url | |||
| domain | |||
| url | |||
| domain | |||
| url | |||
| domain | |||
| url |
Related tags
Frequently asked questions
What is XWorm?
XWorm is a modular .NET Remote Access Trojan and stealer first observed around 2022. It combines keylogging, screen and webcam capture, and credential theft from apps like Telegram, Discord and MetaMask with a plugin system that lets the operator load extra modules per victim, including an optional ransomware plugin. It is not open-source; cracked copies of its builder circulate on underground forums and Telegram channels, most recently a leaked v6.0 build in 2025.
How is XWorm typically delivered?
Most often via phishing email attachments, malicious script loaders (VBS, JS or PowerShell) and trojanised software downloads posing as cracked or pirated tools - the same loader ecosystem used to distribute njRAT and AsyncRAT. The malware does not exploit a vulnerability to install; it relies on the victim executing the dropper.
How is this list updated?
Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. Xworm-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.
What is the license? Can I use this commercially?
All TweetFeed IOC data, including this Xworm subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.
License
Xworm IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).