FILEMembers
FILE

XWorm RAT Campaign Stacks Four Evasion Layers Across 57 Countries

A purchase-order ZIP lure conceals a methodically engineered XWorm delivery chain that bypasses gateway filters, sandbox analysis, and antivirus engines through four discrete evasion techniques. The campaign has reached victims across 57 countries and 15 industry verticals since at least mid-May 2026, with a compile-after-delivery C# component currently registering zero detections across 77 AV engines.

Jun 5, 2026, 08:40 (UTC+9)Last seenJun 14, 2026Severity94ByCTX TeamIOC16MITRE50RegionsAEATAUBDBE

A ZIP archive disguised as a routine purchase-order document is the entry point for one of the more methodically constructed XWorm RAT delivery chains CTX Team has documented in recent months. The campaign — active since at least mid-May 2026 and reaching victims across 57 countries and 15 industry verticals — does not rely on any single clever trick.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence