Trojan:Win32/Xworm!rfn
Trojan:Win32/Xworm!rfn is a specific Win32 version of the XWorm remote access trojan (RAT). This trojan family exists within an amorphous threat ecosystem, with variants also identified in Win64 (native 64-bit Windows binary), VBS (Visual Basic Script) and MSIL (.NET framework) formats. The Win32 iteration differentiates itself as a 32-bit version of the same Win64 variants linked to ClickFix campaign that establishes persistence on Windows devices.
This is done by creating files in user directories like C:\Users\Public\jsc.exe and placing a malicious .url file in the Startup folder. It modifies Windows Registry keys to maintain control and communicates with its command-and-control infrastructure, including the IP address 192[.]3.182.92[:]7006 and domain kribyrisk[.]com. The XWorm’s capabilities include launching remote commands for Windows shutdown, keylogging, screen capture, DDoS attacks, and downloading additional payloads, providing threat actors with comprehensive control over infected devices.