HomeSecurityNew XWorm V6 variant introduces malicious code

New XWorm V6 variant injects malicious code

The reemergence of XWorm in mid-2025 marks a significant escalation in the sophistication of the malware. After a lull following the abrupt end of official support for version 5.6 in late 2024, threat actors unveiled XWorm V6.0 on June 4, 2025. A post on hackforums.net from an account named XCoderTools first announced the release, claiming that it fixes a critical remote code execution bug that existed in previous versions.

See also: XWorm campaign shifts to fileless malware

XWorm V6
New XWorm V6 variant injects malicious code

Despite initial skepticism about the author's authenticity, subsequent samples submitted to VirusTotal confirmed the malware's rapid adoption by cybercriminals. XWorm's modular architecture centers around a core client and a number of add-ons that enable a variety of malicious activities – from credential theft to ransomware deployment.

Once the initial dropper is executed, it uses a multi-stage infection chain designed to evade detection and persist on compromised systems. Trellix noted that the JavaScript installer delivered by the attacker disables the Windows Defender malware scanning interface before launching a PowerShell script that loads a DLL injector.

See also: XWorm: New Infection and Detection Evasion Techniques

New XWorm V6 variant injects malicious code
New XWorm V6 variant injects malicious code

By injecting code into a legitimate Windows process such as RegSvcs.exe, the malware effectively hides its presence within trusted system binaries. Once connected, the client creates a unique machine identifier by hashing a combination of system parameters – username, operating system version, number of processors and directory sizes. This client identifier is stored under HKCU in the registry and is used for all future add-on storage, encryption routines and C2 transactions.

Analysis of the XWorm V6 infection mechanism reveals a carefully orchestrated sequence of actions. The initial payload arrives as a JavaScript (.js) file embedded in phishing emails or compromised websites. When executed, this script issues a PowerShell command that disables AMSI. It then writes the DLL injector and the main XWorm client executable to %TEMP%, before launching the DLL using rundll32.exe.

Using rundll32.exe, the injector maps malicious code into the RegSvcs.exe address space, ensuring that the Trojan executes under a valid process context. This stealthy approach not only bypasses application whitelisting but also complicates forensic analysis by scattering malicious elements across transitive directories.

See also: Variant of XWorm Delivered via Windows Script File

New XWorm V6 variant injects malicious code
New XWorm V6 variant injects malicious code

This memory-based design significantly reduces the malware's footprint and enhances persistence, making detection and remediation particularly challenging for defenders.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS