Worm - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:05:41 UTC Home > List all groups > List all tools > List all groups using tool H-Worm Tool: H-Worm Names H-Worm H-Worm RAT Houdini RAT Houdini Hworm Njw0rm Iniduoh Jenxcus Kognito WSHRAT dinihou dunihi Category Malware Type Backdoor, Info stealer Description (FireEye) H-worm is a VBS (Visual Basic Script) based RAT written by an individual going by the name Houdini. We believe the author is based in Algeria and has connections to njq8, the author of njw0rm and njRAT/LV through means of a shared or common code base. We have seen the H-worm RAT being employed in targeted attacks against the international energy industry; however, we also see it being employed in a wider context as run of the mill attacks through spammed email attachments and malicious links. Information Malpedia AlienVault OTX Last change to this tool card: 29 December 2022 Download this tool card in JSON format All groups using tool H-Worm https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1f72516d-bbb2-465d-b747-94eb664cb96e Page 1 of 2 Changed Name Country Observed APT groups   Molerats, Extreme Jackal, Gaza Cybergang [Gaza] 2012-Jul 2023         ↳ Subgroup: Pat Bear, APT-C-37 2015     TA2541 [Unknown] 2017     WIRTE Group [Middle East] 2018-Feb 2024   4 groups listed (4 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1f72516d-bbb2-465d-b747-94eb664cb96e https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1f72516d-bbb2-465d-b747-94eb664cb96e Page 2 of 2