XWorm 7.2 Malware Campaign Targets Businesses via Phishing Emails

XWorm 7.2 Malware Campaign Targets Businesses via Phishing Emails

First seen 24 Feb 2026, 19:11 UTC HackreadScworld 74% similarity 39.0

Article Content

Browse articles
ThreatCluster

A new phishing campaign is distributing the XWorm 7.2 Remote Access Trojan (RAT) through malicious Excel attachments disguised as business communications. The malware is being sold on Telegram marketplaces, allowing a wider range of cybercriminals to exploit it. Key techniques include hiding the malware within Windows processes and using AES encryption to steal sensitive information.

ThreatCluster AI How this analysis works

Timeline

2018-01-10
CVE-2018-0802 published
2026-02-23
Hackread reports on XWorm 7.2 phishing campaign
2026-02-24
Scworld reports on XWorm malware campaign

Community

Browse all →

Tracked Entities in This Story