Scworld XWorm 7.2 Malware Campaign Targets Businesses via Phishing Emails
Article Content
Browse articles
A new phishing campaign is distributing the XWorm 7.2 Remote Access Trojan (RAT) through malicious Excel attachments disguised as business communications. The malware is being sold on Telegram marketplaces, allowing a wider range of cybercriminals to exploit it. Key techniques include hiding the malware within Windows processes and using AES encryption to steal sensitive information.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
Timeline
2018-01-10
CVE-2018-0802 published
2026-02-23
Hackread reports on XWorm 7.2 phishing campaign
2026-02-24
Scworld reports on XWorm malware campaign
More articles in this cluster (2)
Following this threat?
Track XWorm and CVE-2018-0802 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…
Breeze Comet Targets Brazilian Financial Sector with Systemic Fraud Since 2024, the financially motivated threat actor Breeze Comet has targeted Brazilian financial services, retail, and eCommerce organizations, executing hundreds of fraudulent transactions via the Pix payment system. This group, previously known as UNC5669, employs tactics such as password spraying and social…