FILEMembers
FILE

XWorm RAT Hides C2 Behind Three Evasion Gates in RFQ Phishing Wave

A campaign active since 7 May 2026 delivers XWorm RAT inside ZIP archives disguised as purchase-order documents, targeting procurement staff across 21 countries. Before beaconing to its C2, the payload clears three sequential evasion checks—including a live query to ip-api.com that suppresses network activity inside sandbox environments, keeping the C2 address off automated blocklists.

May 30, 2026, 17:21 (UTC+9)Last seenMay 30, 2026Severity98ByCTX TeamIOC6MITRE40RegionsALAUBDCACN

A pair of Windows executables disguised as purchase-order documents began circulating on 7 May 2026, carrying a commodity remote-access trojan wrapped in enough evasion machinery to slip past automated analysis pipelines and arrive on victim systems with its command-and-control address still largely unknown to the industry. The campaign — tracked by CTX Team under the identifier CTXk3fv3k5gux — delivers XWorm RAT via a ZIP archive whose sole contents are a batch script named to mimic a…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence