Skip to main content

XWorm Malware: Worming Its Way From Entry to Exploitation

0
Medium
Published: 10/05/2026 (10/05/2026, 07:16:30 UTC)
Source: AlienVault OTX General

Description

XWorm is a modular malware associated with the DDGroup cybercrime group that uses multiple delivery methods such as phishing emails, drive-by downloads, exploit kits, USB drives, and RDP exploitation. It performs remote access, data theft including passwords and credit card information, ransomware deployment, spyware installation, and can cause system crashes and denial-of-service attacks. Its modular design and diverse attack vectors make it a persistent and multifaceted threat requiring continuous cybersecurity vigilance.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 09:03:12 UTC

Technical Analysis

XWorm is a versatile modular malware linked to the DDGroup cybercrime group. It employs various infection vectors including phishing emails with malicious attachments, drive-by downloads, exploit kits targeting browser vulnerabilities, USB drives, and exploitation of Remote Desktop Protocol. Once established on a system, XWorm steals sensitive data such as passwords and credit card information, deploys additional malware including ransomware and spyware, and can cause system instability and denial-of-service conditions. Its modular architecture allows it to perform multiple malicious activities including remote access, data theft, ransomware delivery, and botnet creation, making it a complex and persistent threat.

Potential Impact

The malware can lead to unauthorized remote access, theft of sensitive credentials and financial data, deployment of ransomware causing data encryption and potential financial loss, installation of spyware compromising privacy, and disruption of system availability through crashes and denial-of-service attacks.

Defensive Guidance

No specific patch or vendor advisory is available for XWorm. Mitigation requires robust cybersecurity measures including user awareness to prevent phishing, securing Remote Desktop Protocol access, and employing endpoint protection solutions capable of detecting modular malware. Continuous monitoring and incident response readiness are recommended due to the malware's diverse attack vectors and persistence.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://cyberint.com/blog/dark-web/xworm-malware-worming-its-way-from-entry-to-exploitation/"]
Adversary
DDGroup
Pulse Id
6ac34ecea12957741eb7ac1b

Indicators of Compromise

Ip

ValueDescriptionCopy
ip62.60.226.185
—
ip188.212.158.34
—
ip94.154.32.41
—
ip89.106.83.35
—
ip77.110.114.115
—
ip138.124.62.81
—
ip155.103.69.55
—
ip207.189.14.71
—
ip103.131.131.96
—
ip84.38.129.15
—
ip135.136.140.150
—
ip102.220.161.92
—
ip104.249.10.101
—
ip102.220.163.27
—

Hash

ValueDescriptionCopy
hashce02802067934e0eb072f69bf6427bf6
—
hasha06eb79f0ebe4a6999bcc71a2227d8e3
—
hash5f63fe34d77b1eff07a9eef9d7ca1df2537aa90cb1d3fc2e215086d2397313c5
—
hash0718eaa1978c571ddfc9a8c53fdc77eb3b32688831aa3971bd316ca944daacda
—
hash91dff3071d68678e4c1f67675f785372244e9c5952d7a8a100a476323d9d4627
—
hash2b5f0c927f5436d8c04d58bb8c9fba470cbbf4ce23eacf2d65e336ca2bb59d97
—
hash2d28e503d95b6fa5df5b56ea77fdca3a
—
hash3a17c971d67659cfb590bd97f131039c
—
hash7c2b5d3b7535da03eeecb3dacafef353
—
hashc99ed89d7e53d4296aad646b7b19ac96
—
hashd63a77050451cdf76dc317b358d62f84
—
hashfb6e940e3e6ed598a9953950bc4819f7
—
hash2af9f0e9421d3ffcbe4923eea87720c760ca41cd
—
hash49b21cec222b473d2d2ca942d94aec4c02eb6039
—
hash5e6cb6842c63b751a04e14a4a4f9602d5c7bf337
—
hash94b07e3f93813ec17fed88f5a2aba44b22962e5d
—
hash965e01a5974dec5f60461c48550f2b7c314c7cee
—
hashbe312034d50a5e2cf8e25bd4011ad2dbcb876910
—
hash3575a22ba626d0103e8fa5cda194e972e8ec0aa29aa9e9eceb4c48819963bad6
—
hash3e3f0f03a52304570aaf18d4536e8be8a3577e68a198edc53e5877283c18ea5d
—
hash4d403644d7520429283d7e1e4477971fe0b5a418d5e1341f9f12f8f1e84480ee
—
hash9a8dc848fd13565eea98b5e5e9ef222bf2aa9b83df316813ebaff46c1f28c4d3
—
hashd15f8b15696bf2118bf81cf9656f28a6bc6992731956f2e070ce0f033fdd2ef3
—

Domain

ValueDescriptionCopy
domain09090clami09090930032.duckdns.org
—
domainloganwolverin2042.webredirect.org
—
domainmedellin202156.duckdns.org
—
domainfaithbiglovered.opik.net
—
domainxw.jukt.top
—
domainxw.fexd.top
—
domainxw.cizt.top
—
domainxw.bidz.top
—
domainxw.vyqt.top
—
domainxw.vqxt.top
—
domainxw.maxr.top
—
domaininfogruposyc.duckdns.org
—
domainnothinglikefaith.duckdns.org
—
domainebuxsfresh.duckdns.org
—
domainloveyoufaith.duckdns.org
—
domain38.tcp.vip.cpolar.cn
—
domainogo1.duckdns.org
—

Threat ID: 6ac364692cdf04f656e09428

Added to database: 10/05/2026, 08:48:41 UTC

Last enriched: 10/05/2026, 09:03:12 UTC

Last updated: 10/05/2026, 18:48:08 UTC

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses