FILEMembers
FILE

Gaming-Cheat Lures Deploy XWorm RAT and Monero Miner in Europe

A campaign targeting Windows users in Germany and Poland exploits demand for HWID spoofers and skin changers to deliver XWorm RAT and XMRig Monero miner. The operator assembled dedicated Russian-hosted C2 infrastructure one day before the first payload appeared, layering sandbox evasion, debugger detection, and PE timestamp manipulation to suppress activation in analyst environments.

Jun 3, 2026, 20:26 (UTC+9)Last seenJun 3, 2026Severity85ByCTX TeamIOC36MITRE17RegionsDEPL

##Gaming-Cheat Lures Deliver XWorm RAT and Monero Miner to European Windows Users A campaign targeting Windows users in Germany and Poland is exploiting the appetite for gaming-cheat utilities to deliver a dual-payload combination of XWorm remote-access trojan and XMRig Monero miner — a financially motivated operation that layers sandbox evasion, debugger detection, and PE timestamp manipulation to reduce the likelihood of activation in analyst environments.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence