A fresh AlienVault OTX pulse attributed to the DDGroup cybercrime operation confirms that XWorm remains one of the most actively traded and deployed commodity remote access trojans circulating in dark web marketplaces. The pulse surfaces 54 indicators — a mix of C2 IPv4 addresses, dynamic-DNS hostnames, and payload hashes — tied to live campaigns using XWorm for remote access, credential theft, botnet enrollment, and ransomware pre-staging.
This briefing breaks down the threat, operationalizes the indicators, and ships detection content your SOC can deploy today.
Threat Summary
XWorm is a modular, .NET-based remote access trojan sold and distributed across dark web forums and Telegram channels. The OTX data confirms what underground chatter has signaled for months: DDGroup is running XWorm as a multi-purpose intrusion platform rather than a single-objective tool.
The observed attack chain:
- Initial Access — Phishing emails with malicious attachments (archives, weaponized documents, shortcut files), drive-by downloads, and exploit kits targeting browser vulnerabilities.
- Execution — Multi-stage loaders (often obfuscated .NET or scripted droppers) that decrypt and inject the XWorm payload into memory or a hollowed legitimate process.
- Persistence — Registry Run keys, scheduled tasks, and startup folder entries to survive reboot.
- C2 Establishment — Outbound connections to hardcoded IPs or dynamic-DNS domains (the pulse's
duckdns.orghostname is characteristic of this tradecraft). - Objective Execution — Modular capability loading: keylogging, credential harvesting from browsers, screen capture, RDP brute-force/exploitation, botnet enrollment, and downstream ransomware delivery.
The strategic concern: XWorm is increasingly used as an access broker's foothold. A machine compromised by XWorm today may become a ransomware victim next week when DDGroup sells or hands off the access.
Threat Actor / Malware Profile
DDGroup
A cybercrime group operating in the malware-as-a-service ecosystem, associated with XWorm distribution and monetization. Their model spans direct operations (data theft, botnet rental) and indirect monetization (selling access to ransomware affiliates).
XWorm RAT
| Attribute | Detail |
|---|---|
| Type | Modular remote access trojan (.NET) |
| Distribution | Phishing attachments, drive-by downloads, exploit kits, cracked software lures |
| Payload Behavior | Keylogging, browser credential/cookie theft, clipboard hijacking, screen/webcam capture, file exfiltration, remote shell, plugin loading for ransomware staging |
| C2 Communication | TCP sockets to hardcoded IPs and dynamic-DNS (DuckDNS) hostnames; commonly over ports like 7000/4444-style high ports; configuration AES-encrypted in the binary |
| Persistence | HKCU\Software\Microsoft\Windows\CurrentVersion\Run entries, scheduled tasks, startup folder shortcuts |
| Anti-Analysis | Multi-stage decryption, .NET obfuscation, sandbox/VM checks, AMSI bypass attempts, process injection into legitimate binaries (e.g., RegAsm.exe, svchost.exe) |
| Secondary Capability | RDP exploitation for lateral movement, worming propagation attempts |
The RDP exploitation tag in the pulse is significant: compromised hosts are used to brute-force or exploit exposed RDP, converting a single phishing click into network-wide footholds.
IOC Analysis
The pulse contains 54 indicators across three types:
IPv4 C2 Addresses — e.g., 62.60.226.185, 188.212.158.34, 94.154.32.41, 89.106.83.35, 77.110.114.115
- Operationalization: block at egress firewall/proxy immediately; add to threat-intel lookups in your SIEM; retro-search NetFlow/proxy logs for 90 days. Several of these sit on hosting providers frequently abused for bulletproof C2.
Dynamic-DNS Hostname — 09090clami09090930032.duckdns.org
- Operationalization: DNS-sinkhole the FQDN; alert on any historical DNS resolution. DuckDNS domains rotate IPs frequently, so correlate resolution events with the IP list above to catch fast-flux C2.
FileHash-MD5 Payloads — e.g., ce02802067934e0eb072f69bf6427bf6, a06eb79f0ebe4a6999bcc71a2227d8e3
- Operationalization: push hashes to EDR blocklists; sweep file systems and email gateways for historical presence. MD5 hashes are brittle (a single byte change defeats them), so pair hash blocking with the behavioral detections below — behavior is the durable control.
Tooling to decode/enrich: the full indicator set can be exported from OTX as STIX/OpenIOC/CSV for direct ingestion into MISP, Sentinel threat intelligence, or your TIP. Run unknown sibling samples through sandbox detonation (ANY.RUN, Joe Sandbox) to extract configs and net-new C2.
Detection Engineering
---
title: XWorm RAT Persistence via Registry Run Key
id: 9f2c1a44-xworm-0001-aaaa-000000000001
status: experimental
description: Detects registry Run key persistence consistent with XWorm RAT infections attributed to DDGroup. XWorm commonly writes entries under HKCU Run keys pointing to executables in user-writable directories.
author: Security Arsenal Threat Intel
logsource:
category: registry_set
product: windows
detection:
selection_key:
TargetObject|contains:
- '\Software\Microsoft\Windows\CurrentVersion\Run'
selection_path:
Details|contains:
- '\AppData\Roaming\'
- '\AppData\Local\Temp\'
- '\Users\Public\'
- '\ProgramData\'
selection_ext:
Details|endswith:
- '.exe'
- '.bat'
- '.vbs'
- '.ps1'
- '.lnk'
filter_known_good:
Image|endswith:
- '\OneDrive.exe'
- '\Teams.exe'
condition: selection_key and selection_path and selection_ext and not filter_known_good
falsepositives:
- Legitimate user-installed applications registering autostart from AppData
level: high
tags:
- attack.persistence
- attack.t1060
- attack.t1547.001
---
title: XWorm Outbound C2 Connection to Known DDGroup Infrastructure
id: 9f2c1a44-xworm-0002-bbbb-000000000002
status: experimental
description: Detects outbound network connections to XWorm C2 IP addresses and dynamic-DNS hostnames identified in AlienVault OTX pulse attributed to DDGroup.
author: Security Arsenal Threat Intel
logsource:
category: network_connection
product: windows
detection:
selection_ip:
DestinationIp:
- '62.60.226.185'
- '188.212.158.34'
- '94.154.32.41'
- '89.106.83.35'
- '77.110.114.115'
selection_dns:
DestinationHostname|contains:
- '09090clami09090930032.duckdns.org'
- 'duckdns.org'
condition: selection_ip or selection_dns
falsepositives:
- Rare; DuckDNS is abused far more often than used legitimately in enterprise contexts. Validate business use of dynamic DNS before broad allowlisting.
level: critical
tags:
- attack.command_and_control
- attack.t1071
- attack.t1568.001
---
title: XWorm Loader Process Injection into Signed Windows Binaries
id: 9f2c1a44-xworm-0003-cccc-000000000003
status: experimental
description: Detects XWorm's process-hollowing behavior where loaders spawn and inject into legitimate signed .NET/Windows utilities such as RegAsm, MSBuild, or InstallUtil, often launched from script interpreters or Office processes.
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powershell.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\cmd.exe'
selection_child:
Image|endswith:
- '\RegAsm.exe'
- '\MSBuild.exe'
- '\InstallUtil.exe'
- '\RegSvcs.exe'
- '\vbc.exe'
- '\cvtres.exe'
condition: selection_parent and selection_child
falsepositives:
- Legitimate .NET software compilation workflows on developer machines
level: high
tags:
- attack.defense_evasion
- attack.t1055
- attack.t1218
date: 2026/10/05
// XWorm / DDGroup C2 hunt — network connections to OTX-confirmed infrastructure
// plus dynamic-DNS beaconing patterns from unsigned binaries
let XwormIPs = dynamic(["62.60.226.185","188.212.158.34","94.154.32.41","89.106.83.35","77.110.114.115"]);
let XwormDomain = "09090clami09090930032.duckdns.org";
let NetworkHits = DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where RemoteIP in (XwormIPs) or RemoteUrl has "duckdns.org" or RemoteUrl == XwormDomain
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine,
RemoteIP, RemoteUrl, RemotePort, InitiatingProcessSHA256;
let LoaderBehavior = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ ("winword.exe","excel.exe","powershell.exe","wscript.exe","mshta.exe","cmd.exe")
| where FileName in~ ("RegAsm.exe","MSBuild.exe","InstallUtil.exe","RegSvcs.exe","vbc.exe")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256;
union NetworkHits, LoaderBehavior
| sort by TimeGenerated desc
# XWorm / DDGroup Host IOC Hunt — run elevated via RMM/Intune across the fleet
# Checks persistence artifacts, payload hashes, dynamic-DNS resolution, and live C2 connections
$XwormHashes = @("ce02802067934e0eb072f69bf6427bf6","a06eb79f0ebe4a6999bcc71a2227d8e3")
$XwormIPs = @("62.60.226.185","188.212.158.34","94.154.32.41","89.106.83.35","77.110.114.115")
$XwormDomain = "09090clami09090930032.duckdns.org"
$findings = @()
# 1. Registry Run-key persistence pointing at user-writable paths
$runKeys = @("HKCU:\Software\Microsoft\Windows\CurrentVersion\Run",
"HKLM:\Software\Microsoft\Windows\CurrentVersion\Run")
foreach ($key in $runKeys) {
if (Test-Path $key) {
Get-ItemProperty $key | Get-Member -MemberType NoteProperty | ForEach-Object {
$val = (Get-ItemProperty $key -Name $_.Name).($_.Name)
if ($val -match "AppData|Public|ProgramData" -and $val -match "\.(exe|bat|vbs|ps1|lnk)") {
$findings += [pscustomobject]@{Type="RunKeyPersistence"; Detail="$key -> $($_.Name)=$val"}
}
}
}
}
# 2. Scheduled tasks executing from user-writable directories
Get-ScheduledTask | ForEach-Object {
$action = ($_.Actions | Select-Object -First 1).Execute
if ($action -match "AppData|Public|Temp" -and $action -match "\.(exe|bat|vbs|ps1)$") {
$findings += [pscustomobject]@{Type="SuspiciousScheduledTask"; Detail="$($_.TaskName) -> $action"}
}
}
# 3. Hash sweep of common XWorm staging directories
$scanPaths = @("$env:APPDATA","$env:LOCALAPPDATA\Temp","C:\Users\Public","C:\ProgramData")
foreach ($path in $scanPaths) {
if (Test-Path $path) {
Get-ChildItem $path -Recurse -File -Include *.exe,*.dll -ErrorAction SilentlyContinue | ForEach-Object {
$md5 = (Get-FileHash $_.FullName -Algorithm MD5 -ErrorAction SilentlyContinue).Hash
if ($md5 -and ($XwormHashes -contains $md5.ToLower())) {
$findings += [pscustomobject]@{Type="KnownPayloadHash"; Detail="$($_.FullName) MD5=$md5"}
}
}
}
}
# 4. Live and historical network connections to C2
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
Where-Object { $XwormIPs -contains $_.RemoteAddress } | ForEach-Object {
$proc = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
$findings += [pscustomobject]@{Type="ActiveC2Connection"; Detail="$($_.RemoteAddress):$($_.RemotePort) PID=$($_.OwningProcess) Process=$($proc.ProcessName)"}
}
# 5. DNS cache evidence of dynamic-DNS resolution
Get-DnsClientCache -ErrorAction SilentlyContinue | Where-Object { $_.Entry -match "duckdns\.org" } |
ForEach-Object { $findings += [pscustomobject]@{Type="DynamicDNSResolution"; Detail="$($_.Entry) -> $($_.Data)"} }
if ($findings.Count -gt 0) {
$findings | Format-Table -AutoSize
$findings | Export-Csv -Path "$env:TEMP\xworm_hunt_$env:COMPUTERNAME.csv" -NoTypeInformation
Write-Host "[!] $($findings.Count) XWorm indicator(s) found on $env:COMPUTERNAME — isolate and escalate." -ForegroundColor Red
} else {
Write-Host "[+] No XWorm indicators found on $env:COMPUTERNAME." -ForegroundColor Green
}
Response Priorities
Immediate (0–4 hours)
- Block all five C2 IPs and the DuckDNS hostname at the firewall, proxy, and DNS layers. Push the two MD5 hashes to EDR blocklists.
- Retro-hunt 90 days of proxy, DNS, and NetFlow logs for any host that touched this infrastructure — a single hit means assume compromise.
- Deploy the Sigma rules and run the KQL query fleet-wide; execute the PowerShell hunt on any host flagged by either.
24 Hours
- Credential reset for any user on an affected endpoint. XWorm's browser credential and cookie theft means session hijacking is on the table — revoke active sessions/tokens in your IdP, not just passwords.
- Force MFA re-enrollment verification for impacted accounts; check for anomalous logins from new geographies or impossible travel in the exposure window.
- Isolate confirmed hosts for forensic imaging before reimaging — XWorm's modular plugins mean secondary payloads (including ransomware staging) may be resident.
1 Week
- Harden the phishing vector: tighten attachment policies (block/inspect archives, ISOs, and LNK files), deploy detonation for inbound attachments, and run targeted user awareness on the lures observed.
- Restrict RDP exposure: audit internet-facing RDP, enforce VPN/ZTNA gating, enable account lockout and NLA — DDGroup's RDP exploitation tradecraft converts endpoint compromises into lateral movement.
- Attack surface reduction: block Office child processes spawning .NET utilities (RegAsm/MSBuild/InstallUtil), restrict script interpreter execution for standard users, and audit all Run keys and scheduled tasks against a known-good baseline.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.