A new cyber-espionage campaign is distributing the XWorm Remote Access Trojan (RAT) through carefully crafted phishing emails and an old Microsoft Office vulnerability.
Security researchers warn that the operation demonstrates how attackers can still weaponize legacy software flaws to compromise modern systems.
First identified in 2022, XWorm is a powerful Windows malware sold and promoted in underground and Telegram-based markets.
Once installed, it grants attackers full remote control of a victim’s computer, enabling surveillance, file theft, and even ransomware or distributed denial-of-service (DDoS) attacks.
The recent campaign begins with business-style phishing emails sent in multiple languages. Messages pretend to be purchase orders, shipment bank documents, or payment confirmations.
Each email urges the recipient to open an attached Excel add-in file to review details. The attachment is malicious. Opening it silently launches the infection chain.
Excel Exploit Starts Fileless Attack
The Excel document contains a hidden Object Linking and Embedding (OLE) component designed to exploit CVE-2018-0802, a remote code execution flaw in Microsoft Equation Editor.

When the file is opened, the vulnerable program processes malformed data and executes embedded shellcode.
The shellcode downloads an HTML Application (HTA) file onto the system and runs it using Windows utilities.
The HTA script then launches PowerShell, which retrieves a disguised image file from the internet. Hidden inside the image is a .NET malware module encoded in Base64.
Instead of writing files to disk, the module loads directly into memory, making detection harder. It then downloads the final XWorm payload and injects it into a newly created Msbuild.exe process using process hollowing.
This technique replaces the legitimate program’s memory with malicious code while keeping the trusted process name.
The payload analyzed in this campaign corresponds to XWorm version 7.2.

Remote Control, Data Theft, and Plugins
After execution, XWorm connects to its command-and-control (C2) server and registers the infected device.
The malware encrypts communications using AES and transmits system details, including the username, operating system, hardware information, and antivirus software.
Attackers can then send commands to the compromised machine. Capabilities include running programs, downloading files, opening websites, recording keystrokes, capturing screenshots, and controlling the camera or microphone.
The malware can also restart or shut down the computer and execute system commands remotely.
A major feature of XWorm is its plugin architecture. More than 50 optional modules can be loaded from the registry to extend functionality.

These plugins enable credential theft, browser data harvesting, unauthorized remote desktop access, and the launching of DDoS attacks. In some cases, attackers can even deploy ransomware from the same infection.
Researchers say the campaign highlights a recurring security problem: organizations often leave old Office components unpatched. Despite being years old, the Equation Editor vulnerability remains actively exploited because many systems still contain the outdated executable.
Fortinet said, Security experts recommend turning off legacy Office components, applying patches, and treating unexpected attachments with caution. Even a single open document can give attackers complete control of a system within minutes.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.