XWorm Malware: Worming Its Way From Entry to Exploitation
Description
XWorm is a modular malware associated with the DDGroup cybercrime group that uses multiple delivery methods such as phishing emails, drive-by downloads, exploit kits, USB drives, and RDP exploitation. It performs remote access, data theft including passwords and credit card information, ransomware deployment, spyware installation, and can cause system crashes and denial-of-service attacks. Its modular design and diverse attack vectors make it a persistent and multifaceted threat requiring continuous cybersecurity vigilance.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
XWorm is a versatile modular malware linked to the DDGroup cybercrime group. It employs various infection vectors including phishing emails with malicious attachments, drive-by downloads, exploit kits targeting browser vulnerabilities, USB drives, and exploitation of Remote Desktop Protocol. Once established on a system, XWorm steals sensitive data such as passwords and credit card information, deploys additional malware including ransomware and spyware, and can cause system instability and denial-of-service conditions. Its modular architecture allows it to perform multiple malicious activities including remote access, data theft, ransomware delivery, and botnet creation, making it a complex and persistent threat.
Potential Impact
The malware can lead to unauthorized remote access, theft of sensitive credentials and financial data, deployment of ransomware causing data encryption and potential financial loss, installation of spyware compromising privacy, and disruption of system availability through crashes and denial-of-service attacks.
Defensive Guidance
No specific patch or vendor advisory is available for XWorm. Mitigation requires robust cybersecurity measures including user awareness to prevent phishing, securing Remote Desktop Protocol access, and employing endpoint protection solutions capable of detecting modular malware. Continuous monitoring and incident response readiness are recommended due to the malware's diverse attack vectors and persistence.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://cyberint.com/blog/dark-web/xworm-malware-worming-its-way-from-entry-to-exploitation/"]
- Adversary
- DDGroup
- Pulse Id
- 6ac34ecea12957741eb7ac1b
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip62.60.226.185 | — | |
ip188.212.158.34 | — | |
ip94.154.32.41 | — | |
ip89.106.83.35 | — | |
ip77.110.114.115 | — | |
ip138.124.62.81 | — | |
ip155.103.69.55 | — | |
ip207.189.14.71 | — | |
ip103.131.131.96 | — | |
ip84.38.129.15 | — | |
ip135.136.140.150 | — | |
ip102.220.161.92 | — | |
ip104.249.10.101 | — | |
ip102.220.163.27 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashce02802067934e0eb072f69bf6427bf6 | — | |
hasha06eb79f0ebe4a6999bcc71a2227d8e3 | — | |
hash5f63fe34d77b1eff07a9eef9d7ca1df2537aa90cb1d3fc2e215086d2397313c5 | — | |
hash0718eaa1978c571ddfc9a8c53fdc77eb3b32688831aa3971bd316ca944daacda | — | |
hash91dff3071d68678e4c1f67675f785372244e9c5952d7a8a100a476323d9d4627 | — | |
hash2b5f0c927f5436d8c04d58bb8c9fba470cbbf4ce23eacf2d65e336ca2bb59d97 | — | |
hash2d28e503d95b6fa5df5b56ea77fdca3a | — | |
hash3a17c971d67659cfb590bd97f131039c | — | |
hash7c2b5d3b7535da03eeecb3dacafef353 | — | |
hashc99ed89d7e53d4296aad646b7b19ac96 | — | |
hashd63a77050451cdf76dc317b358d62f84 | — | |
hashfb6e940e3e6ed598a9953950bc4819f7 | — | |
hash2af9f0e9421d3ffcbe4923eea87720c760ca41cd | — | |
hash49b21cec222b473d2d2ca942d94aec4c02eb6039 | — | |
hash5e6cb6842c63b751a04e14a4a4f9602d5c7bf337 | — | |
hash94b07e3f93813ec17fed88f5a2aba44b22962e5d | — | |
hash965e01a5974dec5f60461c48550f2b7c314c7cee | — | |
hashbe312034d50a5e2cf8e25bd4011ad2dbcb876910 | — | |
hash3575a22ba626d0103e8fa5cda194e972e8ec0aa29aa9e9eceb4c48819963bad6 | — | |
hash3e3f0f03a52304570aaf18d4536e8be8a3577e68a198edc53e5877283c18ea5d | — | |
hash4d403644d7520429283d7e1e4477971fe0b5a418d5e1341f9f12f8f1e84480ee | — | |
hash9a8dc848fd13565eea98b5e5e9ef222bf2aa9b83df316813ebaff46c1f28c4d3 | — | |
hashd15f8b15696bf2118bf81cf9656f28a6bc6992731956f2e070ce0f033fdd2ef3 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domain09090clami09090930032.duckdns.org | — | |
domainloganwolverin2042.webredirect.org | — | |
domainmedellin202156.duckdns.org | — | |
domainfaithbiglovered.opik.net | — | |
domainxw.jukt.top | — | |
domainxw.fexd.top | — | |
domainxw.cizt.top | — | |
domainxw.bidz.top | — | |
domainxw.vyqt.top | — | |
domainxw.vqxt.top | — | |
domainxw.maxr.top | — | |
domaininfogruposyc.duckdns.org | — | |
domainnothinglikefaith.duckdns.org | — | |
domainebuxsfresh.duckdns.org | — | |
domainloveyoufaith.duckdns.org | — | |
domain38.tcp.vip.cpolar.cn | — | |
domainogo1.duckdns.org | — |
Threat ID: 6ac364692cdf04f656e09428
Added to database: 10/05/2026, 08:48:41 UTC
Last enriched: 10/05/2026, 09:03:12 UTC
Last updated: 10/05/2026, 18:48:08 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.