Furthermore, source code leaks of previous versions have led to dozens of forks, including (focused on banking trojans) and XWorm-Dark (ransomware delivery system).
Windows has largely disabled autorun.inf , but the updated XWorm v31 uses a novel trick: charmap.inf + a shortcut LNK file disguised as a folder. xworm v31 updated
Stay tuned for future updates and developments from xWorm! Furthermore, source code leaks of previous versions have
Injects the XWorm payload into legitimate system processes to hide its activity. XWorm propagates via USB drives
Unlike traditional worms, XWorm propagates via USB drives, network shares, and phishing emails, giving it the "worm" moniker. Version 31 refines all these aspects.
This version is primarily distributed via phishing campaigns and "malvertisement" links (e.g., fake download sites for CrackLink, MediaFire, or gaming cheats).