logo

Hacker infects 18,000 "script kiddies" with fake malware builder

ID: c5219931-edf0-564f-a76b-f3e947c05f05

STIX ID: report--c5219931-edf0-564f-a76b-f3e947c05f05

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A trojanized XWorm RAT “builder” was distributed via GitHub, file hosts, Telegram, YouTube and websites targeting novice ‘script kiddies’; instead of providing a builder it infected users with a backdoor that registered victims to a Telegram-based C2, stole Discord/browser tokens and system data, and supported 56 commands including keylogging, screen capture, file exfiltration and file encryption. Researchers at CloudSEK observed ~18,459 infected devices (majority in Russia, US, India, Ukraine, Turkey), data exfiltration from ~11% of victims, and partly disrupted the botnet by leveraging hard-coded API tokens and a built-in kill switch—though some hosts remain compromised due to offline machines and Telegram rate limits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.