Millenium RAT and XWorm are both Windows remote-access trojans distributed under malware-as-a-service models. The key architectural difference is C2: Millenium RAT abuses the Telegram Bot API, while XWorm has used custom C2 infrastructure.
A notable overlap documented by Group-IB is that trojanized packages masquerading as XWorm were used to deliver Millenium RAT. This is an example of criminal-to-criminal targeting: actors seeking XWorm may download what they believe is an XWorm builder and instead infect themselves with Millenium RAT.
Defensively, both families warrant behavioral detection. Millenium RAT detection emphasizes anomalous Telegram Bot API traffic and AppData persistence; XWorm detection emphasizes its custom C2 protocols. The overlap in distribution means defenders should be aware that offensive-tool communities are themselves a target population.
