Skip to content
Emerging Exploits: SourceWolf and RawrXDA Tools

Emerging Exploits: SourceWolf and RawrXDA Tools

First seen 28 Sep 2026, 02:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 03:34 UTC
  • •SourceWolf targets multiple OS platforms for endpoint scanning.
  • •RawrXDA allows for the creation of Windows executables from scratch.
  • •No confirmed active exploitation of these tools has been reported.

Two new exploits, SourceWolf and RawrXDA, have been reported, targeting various systems. SourceWolf is a scanning tool designed to identify hidden endpoints and extract JavaScript variables, affecting Windows, macOS, and Linux systems. It utilizes the requests library for efficient TCP connection reuse. RawrXDA, on the other hand, is a PE32+ writer and emitter for Windows executables, built entirely in x64 assembly without dependencies. This tool allows for the creation of executable files from scratch, including proper PE headers and section management. Both tools are significant for cybersecurity professionals as they enhance the capabilities of attackers. Current status indicates that these tools are available for use, but no active exploitation has been confirmed yet.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-26
SourceWolf exploit reported
SourceWolf is designed to scan for hidden endpoints and extract JavaScript variables across multiple OS platforms.
Sploitus
2026-09-27
RawrXDA exploit reported
RawrXDA is a PE32+ writer that creates Windows executables from scratch, implemented in x64 assembly.
Sploitus

More articles in this cluster (2)