logo

No Honour Among Thieves: Uncovering a Trojanized XWorm RAT Builder Propagated by Threat Actors and Disrupting Its Operations

ID: 06589bca-31bb-503d-aa49-48d06fc3ce37

STIX ID: report--06589bca-31bb-503d-aa49-48d06fc3ce37

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2025-01-24

Date Updated: 2026-04-27

...
...

### Executive Summary A trojanized XWorm RAT builder has been distributed via GitHub, file-sharing services and Telegram, compromising over 18,459 devices and exfiltrating browser credentials (~1 GB), Discord/Telegram tokens, screenshots and system information; the RAT uses hardcoded Telegram bots for C2, supports a wide command set for full remote control and persistence, and includes a removable 'uninstall' command which researchers used to partially disrupt the botnet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.