Skip to content
XWorm RAT Campaign Utilizes Phishing and CVE-2018-0802 Exploit

XWorm RAT Campaign Utilizes Phishing and CVE-2018-0802 Exploit

First seen 13 Feb 2026, 12:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A new phishing campaign has been detected distributing an updated variant of the XWorm Remote Access Trojan (RAT), which exploits CVE-2018-0802 to evade detection. This campaign targets Microsoft Windows systems and is actively traded in Telegram marketplaces, affecting numerous users since its first tracking in 2022.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

Timeline

2018-02-13
CVE-2018-0802 published
2022-01-01
XWorm first tracked
2026-02-13
New XWorm RAT campaign reported

More articles in this cluster (4)

Following this threat?

Track XWorm in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed