Socprime
XWorm RAT Exploits CVE-2018-0802 in Phishing Campaign
First seen 12 Feb 2026, 22:38 UTC
•
•80% similarity
•54.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A multi-stage phishing campaign has been detected distributing the XWorm remote access trojan (RAT) via malicious Excel attachments. The attack leverages CVE-2018-0802 in Microsoft Equation Editor to execute a fileless .NET loader, which injects XWorm into a new Msbuild.exe process. The RAT utilizes AES-encrypted communication with its command and control server and supports various plugins for extended functionality.
ThreatCluster AI
Timeline
2018-01-10
CVE-2018-0802 published
2018-01-11
First public PoC for CVE-2018-0802
2021-11-03
CVE-2018-0802 added to CISA KEV (active exploitation)
Recent
XWorm phishing campaign observed distributing RAT