Skip to content
XWorm RAT Exploits CVE-2018-0802 in Phishing Campaign

XWorm RAT Exploits CVE-2018-0802 in Phishing Campaign

First seen 12 Feb 2026, 22:38 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A multi-stage phishing campaign has been detected distributing the XWorm remote access trojan (RAT) via malicious Excel attachments. The attack leverages CVE-2018-0802 in Microsoft Equation Editor to execute a fileless .NET loader, which injects XWorm into a new Msbuild.exe process. The RAT utilizes AES-encrypted communication with its command and control server and supports various plugins for extended functionality.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2018-01-10
CVE-2018-0802 published
2018-01-11
First public PoC for CVE-2018-0802
2021-11-03
CVE-2018-0802 added to CISA KEV (active exploitation)
Recent
XWorm phishing campaign observed distributing RAT

More articles in this cluster (1)

Following this threat?

Track XWorm and CVE-2018-0802 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed