Disable administrative privileges for standard users to prevent unauthorized registry modifications. Turn off Windows Script Host (WSH) and PowerShell execution for non-administrative accounts if not operationally required.
The information stealer module has been overhauled to target modern applications:
We are excited to announce the latest update to xWorm, our popular remote access tool (RAT) designed for penetration testers and cybersecurity professionals. xWorm v3.1 is now available, packed with new features, improvements, and enhanced security measures. xworm v31 updated
: Implement strong attachment filtering for ISO, IMG, and VBS files, which are rarely used for legitimate business communication. Network Detection
xWorm v3.1 is widely recognized for its extensive feature set, which allows attackers to gain complete control over a compromised Windows environment. It is frequently sold on dark web forums and Telegram, and "cracked" versions (v3.1 specifically) have been leaked and redistributed within the cybercrime community. Tinexta Defence Core Technical Capabilities xWorm v3
Ensure all systems, especially older Office applications, are fully patched to mitigate vulnerabilities like CVE-2018-0802 .
If you are concerned about a potential infection, I can help you: It is frequently sold on dark web forums
XWorm utilizes TCP sockets for communication rather than standard HTTP/HTTPS protocols used by many other RATs.