andbake.cam: a server that handed out files tagged XWorm, and what to do if a loader on your Windows PC fetched them
andbake.cam is a web address that URLhaus lists four times, on 7 October 2026, for files tagged xworm, and two of them are PNG pictures tagged stego, meaning code hidden inside an image. XWorm is a remote access trojan for Windows, and a picture like that does not infect you by being looked at; it is fetched by a loader that already runs on a PC.
If you only saw the name in a log, nothing is proven. If something on your PC may have fetched these files, treat the PC as watched: change your passwords from another device, then scan and clean or reset Windows.
Facts checked October 11, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like a script, loader or program that downloads files or picture files from andbake.cam usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove andbake.cam (XWorm, stego PNG files) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Andbake.cam (XWorm, stego PNG files): summary
| Type | A malware server: URLhaus tags four files xworm, two of them PNG files also tagged stego. XWorm is a remote access trojan for Windows |
|---|---|
| Risk | High if a loader on your PC fetched its files: keystrokes, passwords, screen, camera and files may be seen or taken. Low if you only saw the name |
| Symptoms | Often none. Unknown scheduled tasks, scripts in the Startup folder and a Defender detection with XWorm in the name are the signs in the reports |
| How to get rid of it | Change passwords from another device, run Microsoft Defender Offline, remove the startup entries, and reset Windows if you are not sure |
| Our check (11 October 2026) | One plain request from our server: the name did not resolve, so no page. That clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Domain registered 21 June 2026; four files reported on 7 October 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows. Nothing we read says Mac or phones are affected |
|---|---|
| Detection names | No detection name is known for the files on this server, because we did not open them. Trend Micro lists Trojan:MSIL/XWorm.C!MTB as the Microsoft name for one XWorm variant |
| Name | Andbake.cam |
| Domain registered | 21 June 2026 |
| Evidence | 4 write-ups by security sites; details still limited |
| First seen | 7 October 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 11 October 2026 |
Facts checked on 11 October 2026 against the URLhaus rows for andbake.cam held in our database (we did not open the abuse.ch host page), RDAP read on 7 October 2026, one plain request from our server that failed at the name lookup, and published pages by Logpoint, AhnLab ASEC, Trend Micro and Microsoft.
We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What andbake.cam is, and what we know about it
andbake.cam is not a program on your PC. It is a web address that the abuse.ch project URLhaus lists as a place where malware was served. We found no public write-up of this one address, so what follows is what URLhaus shows, what we saw ourselves, and what security vendors have published about XWorm and about the picture technique it is tagged with.
- 1
What URLhaus lists
Four file addresses on andbake.cam, all added by the reporter abuse_ch within two minutes on 7 October 2026. Two are pictures named img_ followed by six digits with the ending .png, on the secure https address. Two are short random paths, /HzZgPVc7 and /OhTmRuW3, on plain http. All four carry the threat label malware_download and the tag xworm.
- 2
What the tags mean
xworm is the name of a remote access trojan, a program that lets a stranger control a computer. stego is short for steganography: data hidden inside another file, here inside a picture. Only the two PNG files carry stego. The two short paths carry only xworm, so we cannot say from the tags whether they hand out a script, a program or something else.
- 3
What we could not confirm
We did not download anything from this address, so we cannot tell you what is inside the files, which XWorm build they belong to or where it reports to. URLhaus shows tags, not a proof. We also do not know which email, script or program makes a victim's PC ask for these files. That first step is not visible from the server side.
- 4
What this means for you
If you only saw the name in a firewall log, a blocked request or a warning, you are not infected by that alone. The risk is for a PC where something already ran and went to fetch one of these files. A normal visitor has no reason to ask for a picture called img_233018.png on a domain like this.
- Kind of threat
- A server that handed out four files tagged xworm, two of them PNG files tagged stego; XWorm is a remote access trojan for Windows
- Where the files were
- hxxps://andbake[.]cam/img_233018.png, hxxps://andbake[.]cam/img_233158.png, hxxp://andbake[.]cam/HzZgPVc7 and hxxp://andbake[.]cam/OhTmRuW3
- Domain registered
- 21 June 2026 through NameCheap, Inc.; the only status RDAP showed was client transfer prohibited (RDAP, read 7 October 2026)
- URLhaus entries
- 4 file addresses, all added on 7 October 2026 between 18:24 and 18:26 UTC; all four are marked offline in our copy of the data
- Delivery trick
- Steganography for the two PNG files: code hidden in a picture so a download looks like an image. The entry step on the victim's PC is not known
- Platform
- Windows. XWorm is a .NET remote access trojan for Windows. Nothing we read says these files affect Mac, iPhone or Android
What andbake.cam (XWorm, stego PNG files) does on an infected PC
What we checked on 11 October 2026, and what we could not
Our check was a plain request from our server, not a browser visit and not a screenshot. On 11 October 2026 the name andbake.cam did not resolve: the lookup stopped with the error ENOTFOUND, so there was no page and no file to look at. That clears nothing.
Our check, 11 October 2026
- The name did not resolveOur server could not find an address for andbake.cam (getaddrinfo ENOTFOUND). We do not know why. The domain may have been taken down by its registrar or host after the reports, its DNS records may have been removed by the operator, or the problem may be on one lookup only. We did not test from a second network.
- Why that is not a clean resultA malware server that is offline today can come back under the same name, or under a new one that serves the same files. Operators of this kind of server often move on after a report. A dead address is a good sign for that address and says nothing about the operator or about a PC that already fetched a file.
- Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded.
- URLhaus listingFour file addresses tagged xworm, two of them also tagged stego, added by abuse_ch on 7 October 2026. All four are marked offline in our data.
- Downloads and the files themselvesWe did not download any file. We cannot tell you what the files contain.
Dangerous: treat it as a malware server Our check was one plain request that ended in a name lookup error, so it proves nothing either way. The danger rating comes from the four URLhaus reports and their tags, not from our request. Do not request files from this address and do not run anything that does.
What happened to andbake.cam, from registration to our check
The domain is under four months old and every report comes from two minutes on one evening. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.
21 June 2026
The domain is registered
RDAP shows andbake.cam registered on 21 June 2026 at about 19:33 UTC through NameCheap, Inc. The status list shows client transfer prohibited, which is a standard lock against transfers and not a sign of a takedown.
7 October 2026, 18:24 UTC
Two files are reported
abuse.ch adds https://andbake.cam/img_233158.png (tagged stego and xworm) and http://andbake.cam/HzZgPVc7 (tagged xworm) in the same minute.
7 October 2026, 18:26 UTC
Two more files are reported
abuse.ch adds http://andbake.cam/OhTmRuW3 (tagged xworm) and https://andbake.cam/img_233018.png (tagged stego and xworm). All four files are marked offline in our copy of the data.

All four URLhaus entries for andbake.cam. The two picture names are close together, 233018 and 233158, and the two short paths are random strings. 7 October 2026, evening
Our registration lookup
Our RDAP lookup of the domain succeeds at about 20:08 UTC and shows the registration and the transfer lock. It shows no hold or suspension status.
11 October 2026
The name no longer resolves from our server
Our plain request fails at the name lookup. Four days after the reports we have a domain that was registered, reported and is now not answering. We do not know who ended the service or whether it is still reachable from somewhere else.
What the pattern suggests, and what it does not: four reports in two minutes on a domain registered about three and a half months earlier looks like a server that was used for a short burst and then reported once. That is our reading of the dates, not something any report says. The numbers in the two picture names are consecutive in style (233018 and 233158) and look like a time of day, which would fit files generated in a batch; we cannot confirm that.
How a picture file can carry XWorm
A picture that hides code cannot hurt you by being opened or looked at. It works only when a loader that is already running reads the hidden part and starts it. We did not see the files on andbake.cam; this is how AhnLab ASEC and other vendors describe the technique in XWorm campaigns.

- 1
A first program is already running
AhnLab ASEC describes campaigns that start with a phishing email. The email brings a file or a script, and that first program is what goes out to the internet for the next piece. Nobody has to visit the server by hand.
- 2
It fetches a picture
ASEC found JPG files that contain a .NET loader and, after it, the final malware. In its analysis the loader finds the hidden part by searching the picture for a bitmap signature and then decodes pixel data. The file still shows an ordinary image in a viewer.
- 3
The hidden part is a program
What comes out of the picture is a program, not text. Because the carrier is an image, a filter that only looks at the file type sees nothing unusual. The two PNG files on andbake.cam are tagged stego for exactly this reason, though URLhaus does not say which exact method they use.
- 4
XWorm runs in the background
ASEC says the final XWorm is executed in the background. From then on a person elsewhere can use the PC through it. The next sections list what the sources say it does.
- 5
What the short paths may be
The two paths /HzZgPVc7 and /OhTmRuW3 are eight random characters with no file ending. Links like that are common as a step between a script and a payload, because the server can decide what to hand out. That is our reading; URLhaus tags them only as xworm and we did not fetch them.
What XWorm is
XWorm is a commodity remote access trojan, written for .NET and sold to criminals as a ready made tool. The sources agree on what it does and differ in what each campaign adds around it.
| Question | What the sources say | Source |
|---|---|---|
| What is it? | A remote access trojan sold on dark web markets as malware as a service, able to gather private information and files from the infected computer | Logpoint; Trend Micro |
| What does it do? | Remote desktop viewing, command execution, file theft, credential harvesting, webcam hijacking and keylogging; a module named Xlogger is the keylogger | Logpoint |
| Does it have add ons? | Yes. Version 6 loads plugins that extend the implant, from hidden remote desktop (hVNC) to ransomware. One plugin is a compressed .NET library that steals browser data, Discord tokens and crypto wallet data | Logpoint |
| How does it stay? | In analysed samples through a scheduled task that runs about every minute, or by copying a script into the Startup folder. Not every build behaves the same | Logpoint |
| How does it talk to its controller? | In version 6 over a custom TCP protocol with 256 bit AES encryption, with a key chosen by the attacker when the build is made | Logpoint |
| Who makes it? | Its author, known as XCoder, deleted the account in the second half of 2024 and official support ended. Version 5.6 is presumed the last official one, yet variants keep appearing | Logpoint |
| What does Microsoft call it? | We found no Microsoft encyclopedia page for XWorm. Trend Micro lists the Microsoft detection name Trojan:MSIL/XWorm.C!MTB as an alias for one variant | Trend Micro |
| Which build is this site's? | Not known. URLhaus gives only the tag xworm; we did not open the files | Not available |
What andbake.cam (XWorm, stego PNG files) can steal or download
What XWorm can take from a Windows PC
A remote access trojan gives a person a seat at your computer, so the list below is what such a person can do rather than what one build does automatically. Each item is named by at least one of the sources; no single report lists all of them.
Reported as possible
- Keystrokes, including passwords
- A live view of your screen and hidden remote desktop
- The webcam picture
- Passwords saved in browsers
- Discord tokens
- Cryptocurrency wallet data
- MetaMask and Telegram accounts
- Files searched for and stolen
- Commands run on your PC
- Extra plugins and malware loaded
- Ransomware, through a plugin
| Data | Detail | Source |
|---|---|---|
| Keystrokes and screen | A keylogger module and remote desktop viewing | Logpoint |
| Camera | Webcam hijacking | Logpoint |
| Logins | Credential harvesting; a plugin that targets browsers, Discord tokens and crypto wallets | Logpoint |
| Accounts | Hijacking of MetaMask and Telegram accounts | Trend Micro |
| Files and control | File theft and command execution | Logpoint |
| More malware | Plugins that can reach as far as ransomware | Logpoint |
What this can cost you
Seeing the name in a block list costs you nothing. The risks below apply only to a Windows PC on which a loader fetched one of these files and XWorm then ran.
- High
Passwords and accounts
The keylogger sees each password as you type it, so a new password set on the affected PC is exposed at the moment you choose it. Set new ones only on a device that never ran the files.
- High
Someone using your PC live
The controller does not need to steal everything in one go. They can return days later, wait until you are signed in to a bank or a work tool, and then use the open session.
- High
Crypto and messaging accounts
Vendors name wallet data, MetaMask and Telegram account hijacking. Coins sent from a stolen wallet cannot be called back, and a taken Telegram account is used to reach your contacts.
- Medium
Your documents and your camera
File theft and webcam access are both on the lists, so scans of IDs, contracts and private photos on the PC are within reach.
- Medium
A second or third threat
XWorm loads plugins, and one analysed version 6 plugin family reaches as far as ransomware. A PC that ran it may carry more than one threat.
- Low
Nothing, if you only saw the name
A domain in a block list, a log line or a warning banner is not an infection by itself.
What you may notice, and what you may not
Remote access trojans are built to be quiet. The signs below come from the sources and from what they imply; none is certain, and many victims notice nothing.
| Sign | What the reports show |
|---|---|
| A scheduled task you did not make, especially one that runs every minute | Logpoint describes a sample that created a task through schtasks that runs about once a minute |
| A script or program in the Startup folder that you did not put there | Logpoint describes a PowerShell script that copies itself to the startup folder to stay |
| A Defender detection with XWorm in the name | Trend Micro lists Trojan:MSIL/XWorm.C!MTB as the Microsoft name for one variant. MTB means it was caught by behaviour, not by a fixed signature |
| Your webcam light on, or the mouse moving | The tool can use the camera and the screen. This is our reading of the feature list, not a quote |
| Account activity you did not cause | Sign ins from new places, reset emails you did not ask for, messages you did not send. This is what stolen logins would look like |
| No sign whatsoever | A loader that works in the background is built to stay unseen, so a normal PC proves little |
How to check the PC for andbake.cam (XWorm, stego PNG files)
How a person ends up asking for these files
Nobody visits andbake.cam on purpose. The request comes from a program, so the real question is how that program got on the PC. We cannot say for this server; the route below is the one the vendors found for XWorm with the same picture technique.
- 1
A phishing email with a file
AhnLab ASEC and Trend Micro both describe multi stage attacks that begin with a phishing email. The file looks like a document, an invoice or an order, and opening it or allowing it to run starts the chain.
- 2
A script that pulls the rest
The first file is usually small. It carries no trojan itself; it asks a server for the next piece, which is where a link like the ones on andbake.cam comes in.
- 3
A trojan with no visible window
The last step runs in the background. There is no installer window and no program to uninstall, which is why Settings > Apps rarely shows it.
Check your PC before you delete anything
Start with the question that matters: did something on this PC contact andbake.cam, or did you open an unexpected attachment, script or installer around early October 2026? If you saw the name in a firewall or DNS log on your own network, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.
Until you are done, keep the PC away from banking, email, work and crypto.
- 1
Disconnect first
Switch off Wi-Fi or pull the network cable. Without a connection the controller cannot reach the PC.
- 2
Find which device asked for the address
If this page came up because of a router list, a DNS log or an alert, write down the device name and the time of the request. That one device is the suspect, not the whole home network.
- 3
Open Task Scheduler
Press Start, type Task Scheduler and open it. Look in Task Scheduler Library for tasks you do not know, with random names, or that run a script or a program from a user folder, and for tasks that repeat every minute. Do not delete yet; write the name and the program it runs.
- 4
Look at Startup apps and the Startup folder
Open Settings > Apps > Startup and look for names you did not install. Then press Windows + R, type shell:startup and look for scripts or programs you did not put there.
- 5
Look at running programs
Open Task Manager and sort the Processes tab by CPU and by network use. Look for a process with a name you do not know, or a normal Windows program using a lot of network for no reason. A name alone is not proof, and a clean list does not clear the PC.
- 6
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for a detection with XWorm in the name, or for anything blocked or quarantined at the time of the first contact. Microsoft says the results of an offline scan also appear there.
- 7
Check your accounts from another device
On a phone or another computer, open the recent sign in list of your email, bank, Telegram, Discord and exchange accounts, and look at crypto balances. A strange login tells you more, faster, than any file check.
- 8
A clean scan is not a clean bill of health
Defender or another product finds files it already knows. Read a clean result as one more data point, the same as our own quiet request. We did not infect a PC, so the order of this plan is our judgement from Microsoft's pages and the vendor descriptions, not a tested result.
How to remove andbake.cam (XWorm, stego PNG files)
How to remove andbake.cam
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to andbake.cam or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever andbake.cam installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The tags and every source we read describe a Windows threat. We found nothing that says the files on andbake.cam affect anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | XWorm is described as a .NET program that Windows scripts start | Nothing to remove for this threat; the Windows steps do not apply to a Mac |
| iPhone or iPad | None of the sources we read puts XWorm on iOS | Nothing to remove. Change a password only if you typed it into a page you doubt |
| Android | None of the sources we read mentions it | Nothing to remove for this threat; change any password you entered on a doubtful page |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
Cleaning the PC covers only half of the job. The rest is everything typed or stored on it while XWorm may have been there, and the order matters: accounts from another device first, then the PC.

- 1
Change passwords from a clean device
Begin with your main email, because a reset link for every other account lands there. Then do bank, work, cloud storage, Telegram, Discord and crypto exchanges. Whatever you typed on the PC while XWorm may have been running counts as known. Use a phone or a second computer that never touched the files.
- 2
Sign out other sessions and turn on two step sign in
Most services have a page that signs out all devices. Use it, then switch on two step sign in with an authenticator app or a security key, so a stolen password alone is useless. Check the recovery email and phone number while you are in the settings.
- 3
Move crypto before anything else if a wallet was on the PC
If a seed phrase or a wallet file was ever stored or typed on that PC, assume someone has it. Make a new wallet with a new recovery phrase on a clean device and send the funds there.
- 4
Start an offline scan with Microsoft Defender
Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes. If BitLocker is on the system drive, suspend it first or the restart may ask for the recovery key. Results are under Protection history.
- 5
Remove what the check found, with care
If Task Scheduler or the Startup folder showed an entry you can tie to the malware, delete it once the offline scan is done. If you cannot tell what an entry is, leave it and go to the reset below.
- 6
If you are not sure, reset Windows
Microsoft's recovery page says Reset this PC can be started from Settings or from the Windows recovery environment. In Windows 11 the path is Settings > System > Recovery > Reset this PC. You choose whether to keep or remove personal files; apps and settings are removed either way. For a PC that may have been under remote control, the full wipe with Remove everything is the answer that does not depend on finding every piece. Back up first.
- 7
Restore only documents by hand
Copy back documents and photos only. Do not bring back programs, or a system image taken after the first contact. Reinstall apps from the makers' own sites.
- 8
Keep logins in a password manager
Do not let the browser store passwords again right after a rebuild of a watched PC. A password manager plus an authenticator app or a security key is a better base.
- 9
Keep an eye on money and accounts
Read card statements and exchange histories for the next weeks and switch on alerts. If personal data was taken, report it to your national identity theft or cybercrime service.
- 10
Warn your contacts
If your accounts sent links you did not write, tell the people you message not to open them.
Keep a PC out of this kind of chain
The picture is the late part of the chain. Every vendor write-up we read starts earlier, with a file or a script a person opened.
Do
- Close any attachment that asks you to allow content, run a script or follow a link, unless you asked the sender for it.
- Install Windows and Defender updates as they arrive, so the scans use current definitions.
- Turn on file name extensions in File Explorer, so invoice.pdf.js does not pass as a PDF.
- Download programs from the maker's own site or the Microsoft Store.
- Keep passwords in a password manager and add a second sign in step to the accounts that matter.
- Copy your documents to a drive that stays unplugged between backups.
Don't
- Do not open files from unexpected senders, however much they look like an order or an invoice.
- Do not run cracks, keygens or bundles that promise paid software for free.
- Do not assume a .png is harmless when a script, and not you, asked for it.
- Do not set new passwords on the PC you suspect.
- Do not take a quiet scan, or a dead link, as proof that you are safe.
If you own a website or a domain and it is named here
We do not know whether andbake.cam was bought by the operator or taken from someone else, and we do not say it was hacked. Domains this new are usually registered for the purpose, but a hacked site can also end up on the same list, so this section is for both cases.
- 1
Check what the server really hands out
Look at the files in your web folder and at the access log for the exact paths in this guide. A file such as img_233018.png or a short random path that you never uploaded means someone else has write access.
- 2
Close the way in
Change the passwords of the hosting account, FTP or SSH, the content management system and the database from a clean device. Update the system and its plugins and remove the ones you do not use. Remove the files you did not put there.
- 3
Ask for a review
When the files are gone, ask the host or the listing service to review the address again. abuse.ch runs URLhaus; its pages say how to contest an entry. We could not read that page for this guide, so check it there.
- 4
If the domain is yours but the content is not
If you let the domain lapse or lost the registrar account, contact the registrar's abuse team. Here the registrar is NameCheap, Inc. per RDAP.
Questions about andbake.cam (XWorm, stego PNG files)
What is andbake.cam?
It is a web address that URLhaus, the malware tracking project run by abuse.ch, lists for four files tagged xworm. Two of them are PNG pictures also tagged stego, and two are short random paths.
All four were added on 7 October 2026 within two minutes. It is not a program on your PC and not a website anyone is meant to visit. We did not download the files, so what they contain is not confirmed by us.
Is andbake.cam safe to open?
No. Do not request files from it, and do not run anything that does. On 11 October 2026 the name did not resolve from our server, so there was no page to look at, and that proves nothing: malware servers go offline and come back under the same or a new name.
The rating comes from the four URLhaus reports and their tags, not from our request.
Is XWorm a virus?
XWorm is a remote access trojan, not a virus in the old sense of a program that copies itself into other files. Logpoint describes remote desktop viewing, command execution, file theft, credential harvesting, webcam hijacking and keylogging.
It is sold to criminals as a ready made tool and needs a loader or a phishing file to get onto a PC first. Some versions add plugins, one family of which reaches as far as ransomware.
What does stego mean on a PNG file?
It is short for steganography, hiding data inside another file. AhnLab ASEC describes XWorm campaigns where a .NET loader and the final malware sit inside a picture and a script finds them by searching for a bitmap signature and decoding pixels.
The file still opens as an ordinary picture. A loader that is already running reads the hidden part and starts it, so the picture is a carrier, not something that infects you by being viewed.
I saw andbake.cam in my firewall or DNS log. Am I infected?
Not by that line alone. A log entry says a device asked for the name; it does not say a file arrived or ran.
People rarely type an address like this by hand, so a program probably made the request. Identify the device, take it off the network, and work through the checks above:
- Task Scheduler
- Startup apps
- the Startup folder
- Protection history
- an offline scan
If the log says the request was blocked, the file may never have reached the PC.
How do I remove XWorm from Windows?
Passwords come first, and from another device. After that, run a Microsoft Defender Offline scan (Windows Security, Virus and threat protection, Scan options), then look through Task Scheduler and the Startup folder for entries you did not create and delete those you can link to the malware.
When in doubt, use Reset this PC with Remove everything and bring back documents only. The steps follow Microsoft's pages; we did not run them on an infected PC.
What can XWorm see and take?
Logpoint and Trend Micro list keystrokes, a live view of the screen, stolen files, browser and wallet credentials, Discord tokens and the webcam. Trend Micro also names MetaMask and Telegram account hijacking.
What is taken depends on the person at the controls, who may return later. Count every password, open session and wallet on that PC as exposed and change them from a different device.
Does andbake.cam affect Mac, iPhone or Android?
Nothing we read says so. XWorm is described as a .NET program for Windows, and the loaders in the reports are Windows scripts and programs.
A Mac, an iPhone or an Android phone has nothing to remove for this threat. Change a password only if you typed it into a page you doubt, and check any Windows PC in the same home instead.
Will resetting Windows remove it, and are my accounts safe afterwards?
Yes for the PC, no for what was already taken. Remove everything wipes programs and startup entries, so you do not have to find every piece.
Passwords, open sessions and seed phrases that the trojan saw stay exposed until you change them from another device and add two step sign in. Copy documents back by hand rather than restoring an image made after the first contact.
Will Fortect remove andbake.cam?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For andbake.cam, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Logpoint: XWorm RAT analysis, steal, persist, control (read October 11, 2026)
- AhnLab ASEC: XwormRAT being distributed using steganography (read October 11, 2026)
- Trend Micro threat encyclopedia: TrojanSpy.MSIL.XWORM (lists Microsoft alias Trojan:MSIL/XWorm.C!MTB) (read October 11, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 11, 2026)
- Microsoft Support: Recovery options in Windows (Reset this PC) (read October 11, 2026)