Socprime XWorm RAT Exploits CVE-2018-0802 in Phishing Campaign
Article Content
Browse articles
A multi-stage phishing campaign has been detected distributing the XWorm remote access trojan (RAT) via malicious Excel attachments. The attack leverages CVE-2018-0802 in Microsoft Equation Editor to execute a fileless .NET loader, which injects XWorm into a new Msbuild.exe process. The RAT utilizes AES-encrypted communication with its command and control server and supports various plugins for extended functionality.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
Timeline
2018-01-10
CVE-2018-0802 published
2018-01-11
First public PoC for CVE-2018-0802
2021-11-03
CVE-2018-0802 added to CISA KEV (active exploitation)
Recent
XWorm phishing campaign observed distributing RAT
More articles in this cluster (1)
Following this threat?
Track XWorm and CVE-2018-0802 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…
Breeze Comet Targets Brazilian Financial Sector with Systemic Fraud Since 2024, the financially motivated threat actor Breeze Comet has targeted Brazilian financial services, retail, and eCommerce organizations, executing hundreds of fraudulent transactions via the Pix payment system. This group, previously known as UNC5669, employs tactics such as password spraying and social…