Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New XWorm V6 Variant Embeds Malicious Code into Trusted Windows Applications

XWorm, first detected in 2022, is recognized as a highly effective malware offering a versatile toolkit for cybercriminals. It is designed with a modular architecture consisting of a core client and multiple specialized components known as plugins. These…

XWorm, first detected in 2022, is recognized as a highly effective malware offering a versatile toolkit for cybercriminals. It is designed with a modular architecture consisting of a core client and multiple specialized components known as plugins. These plugins are additional payloads that execute specific malicious actions once the core malware is active.

The modularity of XWorm allows attackers to exploit its capabilities for various objectives, including data theft, system control, and persistent surveillance. Understanding these plugins is essential for cybersecurity professionals and users of cybersecurity products to enhance protection against such threats.

XWorm's development, managed by an individual known as "XCoder," involved regular updates shared through communication platforms. However, after the release of XWorm V5.6 in late 2024, the official support ended, and the developer's account was deleted, leaving V5.6 as the final version at that time. Subsequently, threat actors distributed modified versions of V5.6 with embedded trojans.

A critical vulnerability in V5.6 was disclosed, allowing remote code execution (RCE) by attackers possessing the C2 encryption key. This vulnerability was confirmed in controlled environments.

On June 4, 2025, a new version, XWorm V6.0, was announced, claiming fixes for the RCE flaw and additional enhancements. Despite skepticism regarding the authenticity of the new release, reports indicate a rapid adoption by threat actors.

The XWorm V6.0 campaign typically begins with a malicious JavaScript file that downloads and executes a PowerShell script while displaying a benign PDF decoy. The PowerShell component disables AMSI to avoid detection, retrieves the XWorm client and a DLL injector, and sets them up for stealthy deployment.

The injector embeds XWorm’s code into legitimate Windows programs, allowing covert execution. Once active, the client connects to C2 using a new default key. V6.0 introduces ILProtector-packed plugins stored in registry entries. These plugins support various malicious activities, including remote desktop access, credential theft, file management, and ransomware deployment.

XWorm V6.0 employs persistence scripts via VBS or .wsf files to create scheduled tasks, registry run keys, and other mechanisms to survive system reinstalls. Multiple persistence methods are utilized, ranging from logon scripts to administrative-level reset hooks.

The re-emergence of XWorm underscores the persistent nature of malware threats. Its modular plugin architecture and advanced injection techniques necessitate comprehensive defense strategies beyond traditional signature-based prevention. A multi-layered security approach is crucial, involving endpoint detection and response, proactive email and web gateways, and continuous network monitoring to identify C2 communications.

SHA256 Name

995869775b9d43adeb7e0eb34462164bcfbee3ecb4eda3c436110bd9b905e7ba OSHA_Investigation_Case_0625OQI685837AW.pdf.js

4ce4dc04639d673f0627afc678819d1a7f4b654445ba518a151b2e80e910a92c payload_1.ps1

XWorm, first detected in 2022, is recognized as a highly effective malware offering a versatile toolkit for cybercriminals.
Iris Emerson · Thehackingpost

8514a434b50879e2b8c56cf3fd35f341e24feae5290fa530cc30fae984b0e16c ClassLibrary7.dll

570e4d52b259b460aa17e8e286be64d5bada804bd4757c2475c0e34a73aeb869 XWormClient.exe

000185a17254cd8863208d3828366ec25ddd01596f18e57301355d4a33eac242 RunShell.exe

4d225af71d287f1264f3116075386ac2ce9ee9cd26fb8c3a938c2bf50cca8683 000053AB01136548.wsf

760a3d23ee860cf2686a3d0ef266e7e1ad835cc8b8ce69bfe68765c247753c6b 00001EF600EEBD20.wsf

8106b563e19c946bd76de7d00f7084f3fc3b435ed07eb4757c8da94c89570864 win32.exe

1990659a28b2c194293f106e98f5c5533fdad91e50fdeb1a9590d6b1d2983ada chrome_decrypt.dll

d46bb31dc93b89d67abffe144c56356167c9e57e3235bfb897eafc30626675bb ChromiumDecryption

f279a3fed5b96214d0e3924eedb85907f44d63c7603b074ea975d1ec2fdde0b4 WindowsUpdate.dll

31376631aec4800de046e1400e948936010d9bbedec91c45ae8013c1b87564d0 RemoteDesktop.dll

Advertisement

5123b066f4b864e83bb14060f473cf5155d863f386577586dd6d2826e20e3988 RemoteDesktop.dll

b314836a3ca831fcb068616510572ac32e137ad31ae4b3e506267b429f9129b1 FileManager.dll

5314c7505002cda1e864eced654d132f773722fd621a04ffd84ae9bc0749b791 TCPConnections.dll

33ee1961e302da3abc766480a58c0299b24c6ed8ceeb5803fa857617e37ca96e merged.dll

2b507d3ae01583c8abf4ca0486b918966643159a7c3ee7adb5f36c7bd2e4d70e SystemCheck.Merged.dll

df0096bd57d333ca140331f1c0d54c741a368593a4aac628423ab218b59bd0bb shell.dll

0c2bf36dd9ccb3478c8d3dd7912bcfc1f5d910845446e1adfd1e769490287ab4 Stealer.dll

64cbbbf90fe84eda1a8c2f41a4d37b1d60610e7136a02472a72c28b6acadc2fc Ransomware.dll

6a0c1f70af17bd9258886f997bb43266aa816ff24315050bbf5f0e473d059485 Rootkit.dll

8d04215c281bd7be86f96fd1b24a418ba1c497f5dee3ae1978e4b454b32307a1 ResetSurvival.dll

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories