
XWorm RAT Hides C2 Behind Three Evasion Gates in RFQ Phishing Wave
A campaign active since 7 May 2026 delivers XWorm RAT inside ZIP archives disguised as purchase-order documents, targeting procurement staff across 21 countries. Before beaconing to its C2, the payload clears three sequential evasion checks—including a live query to ip-api.com that suppresses network activity inside sandbox environments, keeping the C2 address off automated blocklists.
A pair of Windows executables disguised as purchase-order documents began circulating on 7 May 2026, carrying a commodity remote-access trojan wrapped in enough evasion machinery to slip past automated analysis pipelines and arrive on victim systems with its command-and-control address still largely unknown to the industry. The campaign — tracked by CTX Team under the identifier CTXk3fv3k5gux — delivers XWorm RAT via a ZIP archive whose sole contents are a batch script named to mimic a…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read