
XWorm V5.6 Deploys 18-Plugin Suite Behind Azure-Hosted C2 Fleet
A fully-assembled XWorm V5.6 toolkit — nineteen files sharing a single build pipeline imphash — has been observed in active deployment across eight countries. All nine command-and-control domains resolve to one Azure IP behind Microsoft-branded nameservers, and eight share a single TLS certificate serial that exposes the campaign's single-operator fingerprint even if individual domains are taken down.
A complete, operationally ready XWorm V5.6 toolkit — nineteen files in total, comprising a main RAT executable and eighteen purpose-built plugin DLLs compiled from a single build pipeline — has been observed in active deployment, with the plugin suite spanning hidden VNC access, keylogging, browser credential theft, ransomware, CMSTP-based UAC bypass, and Windows Defender suppression.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read