APTMembers
APT

XWorm V5.6 Deploys 18-Plugin Suite Behind Azure-Hosted C2 Fleet

A fully-assembled XWorm V5.6 toolkit — nineteen files sharing a single build pipeline imphash — has been observed in active deployment across eight countries. All nine command-and-control domains resolve to one Azure IP behind Microsoft-branded nameservers, and eight share a single TLS certificate serial that exposes the campaign's single-operator fingerprint even if individual domains are taken down.

Jun 17, 2026, 09:42 (UTC+9)Last seenJun 17, 2026Severity100ByCTX TeamActorGamaredon GroupCTIGIOC70MITRE37RegionsBDDEGBINKR

A complete, operationally ready XWorm V5.6 toolkit — nineteen files in total, comprising a main RAT executable and eighteen purpose-built plugin DLLs compiled from a single build pipeline — has been observed in active deployment, with the plugin suite spanning hidden VNC access, keylogging, browser credential theft, ransomware, CMSTP-based UAC bypass, and Windows Defender suppression.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence