Scworld
XWorm 7.2 Malware Campaign Targets Businesses via Phishing Emails
First seen 24 Feb 2026, 19:11 UTC
•
•74% similarity
•39.0
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A new phishing campaign is distributing the XWorm 7.2 Remote Access Trojan (RAT) through malicious Excel attachments disguised as business communications. The malware is being sold on Telegram marketplaces, allowing a wider range of cybercriminals to exploit it. Key techniques include hiding the malware within Windows processes and using AES encryption to steal sensitive information.
ThreatCluster AI
How this analysis works
Timeline
2018-01-10
CVE-2018-0802 published
2026-02-23
Hackread reports on XWorm 7.2 phishing campaign
2026-02-24
Scworld reports on XWorm malware campaign