logo

XWorm malware resurfaces with ransomware module, over 35 plugins

ID: 59711beb-b733-5939-bb3b-cb24d8dc2d2e

STIX ID: report--59711beb-b733-5939-bb3b-cb24d8dc2d2e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-06

Date Updated: 2026-07-17

Author: Ionut Ilascu

...
...

The report details the resurgence of the XWorm remote access trojan (versions 6.0/6.4/6.5) being distributed via phishing and other lures, highlighting its modular architecture with over 35 plugins that provide data theft (from >35 browsers/apps), remote desktop/shell access, and a ransomware module that encrypts user files and drops ransom instructions; researchers observed active campaigns, code overlaps with NoCry ransomware, and multiple delivery techniques that evade protections, and recommend layered defenses including EDR, email/web protections, and network monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.