Join our Telegram channel @MilleniumRatcom for the latest Millenium RAT intelligence updates.

Research Library
comparison

Millenium RAT vs XWorm

Cyber Threat Intelligence Research Team·Published 2026-06-25·Updated 2026-10-04
Summary

Millenium RAT and XWorm are both Windows RATs sold under MaaS models. Millenium abuses Telegram for C2; XWorm uses custom C2. Group-IB observed trojanized XWorm packages delivering Millenium RAT.

Key Takeaways
  • ▸Both are MaaS Windows RATs.
  • ▸Millenium uses Telegram C2; XWorm uses custom C2.
  • ▸Trojanized XWorm packages delivered Millenium RAT.
  • ▸Criminal-to-criminal targeting overlaps both.

Millenium RAT and XWorm are both Windows remote-access trojans distributed under malware-as-a-service models. The key architectural difference is C2: Millenium RAT abuses the Telegram Bot API, while XWorm has used custom C2 infrastructure.

A notable overlap documented by Group-IB is that trojanized packages masquerading as XWorm were used to deliver Millenium RAT. This is an example of criminal-to-criminal targeting: actors seeking XWorm may download what they believe is an XWorm builder and instead infect themselves with Millenium RAT.

Defensively, both families warrant behavioral detection. Millenium RAT detection emphasizes anomalous Telegram Bot API traffic and AppData persistence; XWorm detection emphasizes its custom C2 protocols. The overlap in distribution means defenders should be aware that offensive-tool communities are themselves a target population.

FAQ

Is Millenium RAT related to XWorm?

They are distinct RATs, but trojanized XWorm packages have delivered Millenium RAT.

References

  1. [1]Group-IB, Millenium: A RAT Rewritten, A Threat Multiplied, June 25, 2026

Related Articles

Reviewed byCyber Threat Intelligence Research Team·Last verified: 2026-10-04
Millenium RAT Full Tech package — 0.10 BTC — contact for access