Skip to content
XWorm 7.2 Malware Campaign Targets Businesses via Phishing Emails

XWorm 7.2 Malware Campaign Targets Businesses via Phishing Emails

First seen 24 Feb 2026, 19:11 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A new phishing campaign is distributing the XWorm 7.2 Remote Access Trojan (RAT) through malicious Excel attachments disguised as business communications. The malware is being sold on Telegram marketplaces, allowing a wider range of cybercriminals to exploit it. Key techniques include hiding the malware within Windows processes and using AES encryption to steal sensitive information.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2018-01-10
CVE-2018-0802 published
2026-02-23
Hackread reports on XWorm 7.2 phishing campaign
2026-02-24
Scworld reports on XWorm malware campaign

More articles in this cluster (2)

Following this threat?

Track XWorm and CVE-2018-0802 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed