Cybersecurity researchers have mapped the evolution of the XWorm 6.0 malware, transforming it into a versatile tool to support a wide range of malicious actions on compromised systems.
See also: New XWorm V6 variant injects malicious code

First observed in 2022 and associated with a threat actor named EvilCoder , XWorm is malware that can facilitate data theft, keystroke logging, screen capture, persistence, and even ransomware operations. It is mainly spread through phishing emails and fake websites advertising malicious ScreenConnect installers . Some of the other tools advertised by the developer include a .NET- based malware builder , a remote access trojan called XBinder , and a program that can bypass User Account Control (UAC) restrictions on Windows systems.
In recent years, XWorm's development has been led by an online persona called XCoder. In a report published last month, Trellix described XWorm's evolving infection chains that have used Windows shortcut (LNK) files distributed via phishing emails to execute PowerShell commands that drop a harmless TXT file and a deceptive executable disguised as Discord, which ultimately launches the malware.
XWorm incorporates various anti-analysis and anti-evasion mechanisms to check for signs of a virtualized environment, and if so, immediately stop its execution. The modularity of the malware means that various commands can be issued from an external server to perform actions such as shutting down or rebooting the system, downloading files, opening URLs, and launching DDoS attacks.
See also: XWorm campaign shifts to fileless malware

XWorm’s operations have also faced their own setbacks over the past year, most notably XCoder’s decision to abruptly delete his Telegram account in the second half of 2024, leaving the tool’s future in doubt. Since then, however, threat actors have been seen distributing a cracked version of XWorm version 5.6 that contained malware to infect other threat actors who might download it.
This included attempts by an unknown threat actor to trick script kiddies into downloading a trojanized version of the XWorm RAT builder via GitHub repositories, file sharing services, Telegram channels, and YouTube videos to compromise over 18,459 devices worldwide. This was complemented by attackers distributing modified versions of XWorm – one of which is a Chinese variant codenamed XSPY – as well as the discovery of a remote code execution (RCE) vulnerability in the malware that allows attackers with the C2 encryption key to execute arbitrary code.
While XCoder’s apparent abandonment of XWorm has raised the possibility that the project is “closed for good,” Trellix said it spotted a threat actor going by the name XCoderTools offering XWorm 6.0 on a cybercrime forum on June 4, 2025, for $500 for lifetime access, describing it as a “fully recoded” version with a fix for the aforementioned RCE vulnerability. It is not currently known whether the latest version is the work of the same developer or someone else exploiting the malware’s reputation.
See also: XWorm: New Infection and Detection Evasion Techniques

Campaigns distributing XWorm 6.0 have used malicious JavaScript in phishing emails that, when opened, display a deceptive PDF document, while in the background, PowerShell code is executed to inject the malware into a legitimate Windows process such as RegSvcs.exe without causing any attention.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
