andbake.cam: a server that handed out files tagged XWorm, and what to do if a loader on your Windows PC fetched them

andbake.cam is a web address that URLhaus lists four times, on 7 October 2026, for files tagged xworm, and two of them are PNG pictures tagged stego, meaning code hidden inside an image. XWorm is a remote access trojan for Windows, and a picture like that does not infect you by being looked at; it is fetched by a loader that already runs on a PC.

If you only saw the name in a log, nothing is proven. If something on your PC may have fetched these files, treat the PC as watched: change your passwords from another device, then scan and clean or reset Windows.

Facts checked October 11, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Programs like a script, loader or program that downloads files or picture files from andbake.cam usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove andbake.cam (XWorm, stego PNG files) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of four URLhaus entries for andbake.cam added on 7 October 2026, two short paths and two img PNG files, all tagged xworm, the PNG files also tagged stego, all offline
The four URLhaus entries for andbake.cam as they are in our data. Our own request to the site did not resolve, so this table of reports, not a screenshot of the site, is the main evidence.

Andbake.cam (XWorm, stego PNG files): summary

TypeA malware server: URLhaus tags four files xworm, two of them PNG files also tagged stego. XWorm is a remote access trojan for Windows
RiskHigh if a loader on your PC fetched its files: keystrokes, passwords, screen, camera and files may be seen or taken. Low if you only saw the name
SymptomsOften none. Unknown scheduled tasks, scripts in the Startup folder and a Defender detection with XWorm in the name are the signs in the reports
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove the startup entries, and reset Windows if you are not sure
Our check (11 October 2026)One plain request from our server: the name did not resolve, so no page. That clears nothing; the danger rating comes from URLhaus
Running since / first seenDomain registered 21 June 2026; four files reported on 7 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows. Nothing we read says Mac or phones are affected
Detection namesNo detection name is known for the files on this server, because we did not open them. Trend Micro lists Trojan:MSIL/XWorm.C!MTB as the Microsoft name for one XWorm variant
NameAndbake.cam
Domain registered21 June 2026
Evidence4 write-ups by security sites; details still limited
First seen7 October 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked11 October 2026

Facts checked on 11 October 2026 against the URLhaus rows for andbake.cam held in our database (we did not open the abuse.ch host page), RDAP read on 7 October 2026, one plain request from our server that failed at the name lookup, and published pages by Logpoint, AhnLab ASEC, Trend Micro and Microsoft.

We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What andbake.cam is, and what we know about it

andbake.cam is not a program on your PC. It is a web address that the abuse.ch project URLhaus lists as a place where malware was served. We found no public write-up of this one address, so what follows is what URLhaus shows, what we saw ourselves, and what security vendors have published about XWorm and about the picture technique it is tagged with.

  1. 1

    What URLhaus lists

    Four file addresses on andbake.cam, all added by the reporter abuse_ch within two minutes on 7 October 2026. Two are pictures named img_ followed by six digits with the ending .png, on the secure https address. Two are short random paths, /HzZgPVc7 and /OhTmRuW3, on plain http. All four carry the threat label malware_download and the tag xworm.

  2. 2

    What the tags mean

    xworm is the name of a remote access trojan, a program that lets a stranger control a computer. stego is short for steganography: data hidden inside another file, here inside a picture. Only the two PNG files carry stego. The two short paths carry only xworm, so we cannot say from the tags whether they hand out a script, a program or something else.

  3. 3

    What we could not confirm

    We did not download anything from this address, so we cannot tell you what is inside the files, which XWorm build they belong to or where it reports to. URLhaus shows tags, not a proof. We also do not know which email, script or program makes a victim's PC ask for these files. That first step is not visible from the server side.

  4. 4

    What this means for you

    If you only saw the name in a firewall log, a blocked request or a warning, you are not infected by that alone. The risk is for a PC where something already ran and went to fetch one of these files. A normal visitor has no reason to ask for a picture called img_233018.png on a domain like this.

Kind of threat
A server that handed out four files tagged xworm, two of them PNG files tagged stego; XWorm is a remote access trojan for Windows
Where the files were
hxxps://andbake[.]cam/img_233018.png, hxxps://andbake[.]cam/img_233158.png, hxxp://andbake[.]cam/HzZgPVc7 and hxxp://andbake[.]cam/OhTmRuW3
Domain registered
21 June 2026 through NameCheap, Inc.; the only status RDAP showed was client transfer prohibited (RDAP, read 7 October 2026)
URLhaus entries
4 file addresses, all added on 7 October 2026 between 18:24 and 18:26 UTC; all four are marked offline in our copy of the data
Delivery trick
Steganography for the two PNG files: code hidden in a picture so a download looks like an image. The entry step on the victim's PC is not known
Platform
Windows. XWorm is a .NET remote access trojan for Windows. Nothing we read says these files affect Mac, iPhone or Android

What andbake.cam (XWorm, stego PNG files) does on an infected PC

What we checked on 11 October 2026, and what we could not

Our check was a plain request from our server, not a browser visit and not a screenshot. On 11 October 2026 the name andbake.cam did not resolve: the lookup stopped with the error ENOTFOUND, so there was no page and no file to look at. That clears nothing.

Our check, 11 October 2026

  • The name did not resolveOur server could not find an address for andbake.cam (getaddrinfo ENOTFOUND). We do not know why. The domain may have been taken down by its registrar or host after the reports, its DNS records may have been removed by the operator, or the problem may be on one lookup only. We did not test from a second network.
  • Why that is not a clean resultA malware server that is offline today can come back under the same name, or under a new one that serves the same files. Operators of this kind of server often move on after a report. A dead address is a good sign for that address and says nothing about the operator or about a PC that already fetched a file.
  • Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded.
  • URLhaus listingFour file addresses tagged xworm, two of them also tagged stego, added by abuse_ch on 7 October 2026. All four are marked offline in our data.
  • Downloads and the files themselvesWe did not download any file. We cannot tell you what the files contain.

Dangerous: treat it as a malware server Our check was one plain request that ended in a name lookup error, so it proves nothing either way. The danger rating comes from the four URLhaus reports and their tags, not from our request. Do not request files from this address and do not run anything that does.

What happened to andbake.cam, from registration to our check

The domain is under four months old and every report comes from two minutes on one evening. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.

  1. 21 June 2026

    The domain is registered

    RDAP shows andbake.cam registered on 21 June 2026 at about 19:33 UTC through NameCheap, Inc. The status list shows client transfer prohibited, which is a standard lock against transfers and not a sign of a takedown.

  2. 7 October 2026, 18:24 UTC

    Two files are reported

    abuse.ch adds https://andbake.cam/img_233158.png (tagged stego and xworm) and http://andbake.cam/HzZgPVc7 (tagged xworm) in the same minute.

  3. 7 October 2026, 18:26 UTC

    Two more files are reported

    abuse.ch adds http://andbake.cam/OhTmRuW3 (tagged xworm) and https://andbake.cam/img_233018.png (tagged stego and xworm). All four files are marked offline in our copy of the data.

    Table of the four URLhaus entries for andbake.cam with times, file addresses, tags and offline status
    All four URLhaus entries for andbake.cam. The two picture names are close together, 233018 and 233158, and the two short paths are random strings.
  4. 7 October 2026, evening

    Our registration lookup

    Our RDAP lookup of the domain succeeds at about 20:08 UTC and shows the registration and the transfer lock. It shows no hold or suspension status.

  5. 11 October 2026

    The name no longer resolves from our server

    Our plain request fails at the name lookup. Four days after the reports we have a domain that was registered, reported and is now not answering. We do not know who ended the service or whether it is still reachable from somewhere else.

What the pattern suggests, and what it does not: four reports in two minutes on a domain registered about three and a half months earlier looks like a server that was used for a short burst and then reported once. That is our reading of the dates, not something any report says. The numbers in the two picture names are consecutive in style (233018 and 233158) and look like a time of day, which would fit files generated in a batch; we cannot confirm that.

How a picture file can carry XWorm

A picture that hides code cannot hurt you by being opened or looked at. It works only when a loader that is already running reads the hidden part and starts it. We did not see the files on andbake.cam; this is how AhnLab ASEC and other vendors describe the technique in XWorm campaigns.

Four steps: a phishing email brings a script, the script asks a server for a short link, it fetches a PNG and reads the hidden bytes, XWorm runs in the background and calls home
The picture trick in four steps, as vendors describe it for XWorm. The entry step on a victim's PC is not something we saw.
  1. 1

    A first program is already running

    AhnLab ASEC describes campaigns that start with a phishing email. The email brings a file or a script, and that first program is what goes out to the internet for the next piece. Nobody has to visit the server by hand.

  2. 2

    It fetches a picture

    ASEC found JPG files that contain a .NET loader and, after it, the final malware. In its analysis the loader finds the hidden part by searching the picture for a bitmap signature and then decodes pixel data. The file still shows an ordinary image in a viewer.

  3. 3

    The hidden part is a program

    What comes out of the picture is a program, not text. Because the carrier is an image, a filter that only looks at the file type sees nothing unusual. The two PNG files on andbake.cam are tagged stego for exactly this reason, though URLhaus does not say which exact method they use.

  4. 4

    XWorm runs in the background

    ASEC says the final XWorm is executed in the background. From then on a person elsewhere can use the PC through it. The next sections list what the sources say it does.

  5. 5

    What the short paths may be

    The two paths /HzZgPVc7 and /OhTmRuW3 are eight random characters with no file ending. Links like that are common as a step between a script and a payload, because the server can decide what to hand out. That is our reading; URLhaus tags them only as xworm and we did not fetch them.

What XWorm is

XWorm is a commodity remote access trojan, written for .NET and sold to criminals as a ready made tool. The sources agree on what it does and differ in what each campaign adds around it.

Sources: Logpoint, Trend Micro threat encyclopedia and AhnLab ASEC, read 11 October 2026.
QuestionWhat the sources saySource
What is it?A remote access trojan sold on dark web markets as malware as a service, able to gather private information and files from the infected computerLogpoint; Trend Micro
What does it do?Remote desktop viewing, command execution, file theft, credential harvesting, webcam hijacking and keylogging; a module named Xlogger is the keyloggerLogpoint
Does it have add ons?Yes. Version 6 loads plugins that extend the implant, from hidden remote desktop (hVNC) to ransomware. One plugin is a compressed .NET library that steals browser data, Discord tokens and crypto wallet dataLogpoint
How does it stay?In analysed samples through a scheduled task that runs about every minute, or by copying a script into the Startup folder. Not every build behaves the sameLogpoint
How does it talk to its controller?In version 6 over a custom TCP protocol with 256 bit AES encryption, with a key chosen by the attacker when the build is madeLogpoint
Who makes it?Its author, known as XCoder, deleted the account in the second half of 2024 and official support ended. Version 5.6 is presumed the last official one, yet variants keep appearingLogpoint
What does Microsoft call it?We found no Microsoft encyclopedia page for XWorm. Trend Micro lists the Microsoft detection name Trojan:MSIL/XWorm.C!MTB as an alias for one variantTrend Micro
Which build is this site's?Not known. URLhaus gives only the tag xworm; we did not open the filesNot available

What andbake.cam (XWorm, stego PNG files) can steal or download

What XWorm can take from a Windows PC

A remote access trojan gives a person a seat at your computer, so the list below is what such a person can do rather than what one build does automatically. Each item is named by at least one of the sources; no single report lists all of them.

Reported as possible

  • Keystrokes, including passwords
  • A live view of your screen and hidden remote desktop
  • The webcam picture
  • Passwords saved in browsers
  • Discord tokens
  • Cryptocurrency wallet data
  • MetaMask and Telegram accounts
  • Files searched for and stolen
  • Commands run on your PC
  • Extra plugins and malware loaded
  • Ransomware, through a plugin
Sources: Logpoint and Trend Micro, read 11 October 2026.
DataDetailSource
Keystrokes and screenA keylogger module and remote desktop viewingLogpoint
CameraWebcam hijackingLogpoint
LoginsCredential harvesting; a plugin that targets browsers, Discord tokens and crypto walletsLogpoint
AccountsHijacking of MetaMask and Telegram accountsTrend Micro
Files and controlFile theft and command executionLogpoint
More malwarePlugins that can reach as far as ransomwareLogpoint

What this can cost you

Seeing the name in a block list costs you nothing. The risks below apply only to a Windows PC on which a loader fetched one of these files and XWorm then ran.

  • High

    Passwords and accounts

    The keylogger sees each password as you type it, so a new password set on the affected PC is exposed at the moment you choose it. Set new ones only on a device that never ran the files.

  • High

    Someone using your PC live

    The controller does not need to steal everything in one go. They can return days later, wait until you are signed in to a bank or a work tool, and then use the open session.

  • High

    Crypto and messaging accounts

    Vendors name wallet data, MetaMask and Telegram account hijacking. Coins sent from a stolen wallet cannot be called back, and a taken Telegram account is used to reach your contacts.

  • Medium

    Your documents and your camera

    File theft and webcam access are both on the lists, so scans of IDs, contracts and private photos on the PC are within reach.

  • Medium

    A second or third threat

    XWorm loads plugins, and one analysed version 6 plugin family reaches as far as ransomware. A PC that ran it may carry more than one threat.

  • Low

    Nothing, if you only saw the name

    A domain in a block list, a log line or a warning banner is not an infection by itself.

What you may notice, and what you may not

Remote access trojans are built to be quiet. The signs below come from the sources and from what they imply; none is certain, and many victims notice nothing.

SignWhat the reports show
A scheduled task you did not make, especially one that runs every minuteLogpoint describes a sample that created a task through schtasks that runs about once a minute
A script or program in the Startup folder that you did not put thereLogpoint describes a PowerShell script that copies itself to the startup folder to stay
A Defender detection with XWorm in the nameTrend Micro lists Trojan:MSIL/XWorm.C!MTB as the Microsoft name for one variant. MTB means it was caught by behaviour, not by a fixed signature
Your webcam light on, or the mouse movingThe tool can use the camera and the screen. This is our reading of the feature list, not a quote
Account activity you did not causeSign ins from new places, reset emails you did not ask for, messages you did not send. This is what stolen logins would look like
No sign whatsoeverA loader that works in the background is built to stay unseen, so a normal PC proves little

How to check the PC for andbake.cam (XWorm, stego PNG files)

How a person ends up asking for these files

Nobody visits andbake.cam on purpose. The request comes from a program, so the real question is how that program got on the PC. We cannot say for this server; the route below is the one the vendors found for XWorm with the same picture technique.

  1. 1

    A phishing email with a file

    AhnLab ASEC and Trend Micro both describe multi stage attacks that begin with a phishing email. The file looks like a document, an invoice or an order, and opening it or allowing it to run starts the chain.

  2. 2

    A script that pulls the rest

    The first file is usually small. It carries no trojan itself; it asks a server for the next piece, which is where a link like the ones on andbake.cam comes in.

  3. 3

    A trojan with no visible window

    The last step runs in the background. There is no installer window and no program to uninstall, which is why Settings > Apps rarely shows it.

Check your PC before you delete anything

Start with the question that matters: did something on this PC contact andbake.cam, or did you open an unexpected attachment, script or installer around early October 2026? If you saw the name in a firewall or DNS log on your own network, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.

Until you are done, keep the PC away from banking, email, work and crypto.

  1. 1

    Disconnect first

    Switch off Wi-Fi or pull the network cable. Without a connection the controller cannot reach the PC.

  2. 2

    Find which device asked for the address

    If this page came up because of a router list, a DNS log or an alert, write down the device name and the time of the request. That one device is the suspect, not the whole home network.

  3. 3

    Open Task Scheduler

    Press Start, type Task Scheduler and open it. Look in Task Scheduler Library for tasks you do not know, with random names, or that run a script or a program from a user folder, and for tasks that repeat every minute. Do not delete yet; write the name and the program it runs.

  4. 4

    Look at Startup apps and the Startup folder

    Open Settings > Apps > Startup and look for names you did not install. Then press Windows + R, type shell:startup and look for scripts or programs you did not put there.

  5. 5

    Look at running programs

    Open Task Manager and sort the Processes tab by CPU and by network use. Look for a process with a name you do not know, or a normal Windows program using a lot of network for no reason. A name alone is not proof, and a clean list does not clear the PC.

  6. 6

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for a detection with XWorm in the name, or for anything blocked or quarantined at the time of the first contact. Microsoft says the results of an offline scan also appear there.

  7. 7

    Check your accounts from another device

    On a phone or another computer, open the recent sign in list of your email, bank, Telegram, Discord and exchange accounts, and look at crypto balances. A strange login tells you more, faster, than any file check.

  8. 8

    A clean scan is not a clean bill of health

    Defender or another product finds files it already knows. Read a clean result as one more data point, the same as our own quiet request. We did not infect a PC, so the order of this plan is our judgement from Microsoft's pages and the vendor descriptions, not a tested result.

How to remove andbake.cam (XWorm, stego PNG files)

How to remove andbake.cam

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to andbake.cam or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever andbake.cam installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The tags and every source we read describe a Windows threat. We found nothing that says the files on andbake.cam affect anything else.

Your deviceWhat we knowWhat to do
MacXWorm is described as a .NET program that Windows scripts startNothing to remove for this threat; the Windows steps do not apply to a Mac
iPhone or iPadNone of the sources we read puts XWorm on iOSNothing to remove. Change a password only if you typed it into a page you doubt
AndroidNone of the sources we read mentions itNothing to remove for this threat; change any password you entered on a doubtful page

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

Cleaning the PC covers only half of the job. The rest is everything typed or stored on it while XWorm may have been there, and the order matters: accounts from another device first, then the PC.

Five steps in order: disconnect the PC, change passwords from another device, run a Defender Offline scan, check scheduled tasks and Startup apps, reset Windows if unsure
The order of actions if a loader like this ran on a PC. Steps follow Microsoft's pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Begin with your main email, because a reset link for every other account lands there. Then do bank, work, cloud storage, Telegram, Discord and crypto exchanges. Whatever you typed on the PC while XWorm may have been running counts as known. Use a phone or a second computer that never touched the files.

  2. 2

    Sign out other sessions and turn on two step sign in

    Most services have a page that signs out all devices. Use it, then switch on two step sign in with an authenticator app or a security key, so a stolen password alone is useless. Check the recovery email and phone number while you are in the settings.

  3. 3

    Move crypto before anything else if a wallet was on the PC

    If a seed phrase or a wallet file was ever stored or typed on that PC, assume someone has it. Make a new wallet with a new recovery phrase on a clean device and send the funds there.

  4. 4

    Start an offline scan with Microsoft Defender

    Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes. If BitLocker is on the system drive, suspend it first or the restart may ask for the recovery key. Results are under Protection history.

  5. 5

    Remove what the check found, with care

    If Task Scheduler or the Startup folder showed an entry you can tie to the malware, delete it once the offline scan is done. If you cannot tell what an entry is, leave it and go to the reset below.

  6. 6

    If you are not sure, reset Windows

    Microsoft's recovery page says Reset this PC can be started from Settings or from the Windows recovery environment. In Windows 11 the path is Settings > System > Recovery > Reset this PC. You choose whether to keep or remove personal files; apps and settings are removed either way. For a PC that may have been under remote control, the full wipe with Remove everything is the answer that does not depend on finding every piece. Back up first.

  7. 7

    Restore only documents by hand

    Copy back documents and photos only. Do not bring back programs, or a system image taken after the first contact. Reinstall apps from the makers' own sites.

  8. 8

    Keep logins in a password manager

    Do not let the browser store passwords again right after a rebuild of a watched PC. A password manager plus an authenticator app or a security key is a better base.

  9. 9

    Keep an eye on money and accounts

    Read card statements and exchange histories for the next weeks and switch on alerts. If personal data was taken, report it to your national identity theft or cybercrime service.

  10. 10

    Warn your contacts

    If your accounts sent links you did not write, tell the people you message not to open them.

Keep a PC out of this kind of chain

The picture is the late part of the chain. Every vendor write-up we read starts earlier, with a file or a script a person opened.

Do

  • Close any attachment that asks you to allow content, run a script or follow a link, unless you asked the sender for it.
  • Install Windows and Defender updates as they arrive, so the scans use current definitions.
  • Turn on file name extensions in File Explorer, so invoice.pdf.js does not pass as a PDF.
  • Download programs from the maker's own site or the Microsoft Store.
  • Keep passwords in a password manager and add a second sign in step to the accounts that matter.
  • Copy your documents to a drive that stays unplugged between backups.

Don't

  • Do not open files from unexpected senders, however much they look like an order or an invoice.
  • Do not run cracks, keygens or bundles that promise paid software for free.
  • Do not assume a .png is harmless when a script, and not you, asked for it.
  • Do not set new passwords on the PC you suspect.
  • Do not take a quiet scan, or a dead link, as proof that you are safe.

If you own a website or a domain and it is named here

We do not know whether andbake.cam was bought by the operator or taken from someone else, and we do not say it was hacked. Domains this new are usually registered for the purpose, but a hacked site can also end up on the same list, so this section is for both cases.

  1. 1

    Check what the server really hands out

    Look at the files in your web folder and at the access log for the exact paths in this guide. A file such as img_233018.png or a short random path that you never uploaded means someone else has write access.

  2. 2

    Close the way in

    Change the passwords of the hosting account, FTP or SSH, the content management system and the database from a clean device. Update the system and its plugins and remove the ones you do not use. Remove the files you did not put there.

  3. 3

    Ask for a review

    When the files are gone, ask the host or the listing service to review the address again. abuse.ch runs URLhaus; its pages say how to contest an entry. We could not read that page for this guide, so check it there.

  4. 4

    If the domain is yours but the content is not

    If you let the domain lapse or lost the registrar account, contact the registrar's abuse team. Here the registrar is NameCheap, Inc. per RDAP.

Questions about andbake.cam (XWorm, stego PNG files)

What is andbake.cam?

It is a web address that URLhaus, the malware tracking project run by abuse.ch, lists for four files tagged xworm. Two of them are PNG pictures also tagged stego, and two are short random paths.

All four were added on 7 October 2026 within two minutes. It is not a program on your PC and not a website anyone is meant to visit. We did not download the files, so what they contain is not confirmed by us.

Is andbake.cam safe to open?

No. Do not request files from it, and do not run anything that does. On 11 October 2026 the name did not resolve from our server, so there was no page to look at, and that proves nothing: malware servers go offline and come back under the same or a new name.

The rating comes from the four URLhaus reports and their tags, not from our request.

Is XWorm a virus?

XWorm is a remote access trojan, not a virus in the old sense of a program that copies itself into other files. Logpoint describes remote desktop viewing, command execution, file theft, credential harvesting, webcam hijacking and keylogging.

It is sold to criminals as a ready made tool and needs a loader or a phishing file to get onto a PC first. Some versions add plugins, one family of which reaches as far as ransomware.

What does stego mean on a PNG file?

It is short for steganography, hiding data inside another file. AhnLab ASEC describes XWorm campaigns where a .NET loader and the final malware sit inside a picture and a script finds them by searching for a bitmap signature and decoding pixels.

The file still opens as an ordinary picture. A loader that is already running reads the hidden part and starts it, so the picture is a carrier, not something that infects you by being viewed.

I saw andbake.cam in my firewall or DNS log. Am I infected?

Not by that line alone. A log entry says a device asked for the name; it does not say a file arrived or ran.

People rarely type an address like this by hand, so a program probably made the request. Identify the device, take it off the network, and work through the checks above:

  • Task Scheduler
  • Startup apps
  • the Startup folder
  • Protection history
  • an offline scan

If the log says the request was blocked, the file may never have reached the PC.

How do I remove XWorm from Windows?

Passwords come first, and from another device. After that, run a Microsoft Defender Offline scan (Windows Security, Virus and threat protection, Scan options), then look through Task Scheduler and the Startup folder for entries you did not create and delete those you can link to the malware.

When in doubt, use Reset this PC with Remove everything and bring back documents only. The steps follow Microsoft's pages; we did not run them on an infected PC.

What can XWorm see and take?

Logpoint and Trend Micro list keystrokes, a live view of the screen, stolen files, browser and wallet credentials, Discord tokens and the webcam. Trend Micro also names MetaMask and Telegram account hijacking.

What is taken depends on the person at the controls, who may return later. Count every password, open session and wallet on that PC as exposed and change them from a different device.

Does andbake.cam affect Mac, iPhone or Android?

Nothing we read says so. XWorm is described as a .NET program for Windows, and the loaders in the reports are Windows scripts and programs.

A Mac, an iPhone or an Android phone has nothing to remove for this threat. Change a password only if you typed it into a page you doubt, and check any Windows PC in the same home instead.

Will resetting Windows remove it, and are my accounts safe afterwards?

Yes for the PC, no for what was already taken. Remove everything wipes programs and startup entries, so you do not have to find every piece.

Passwords, open sessions and seed phrases that the trojan saw stay exposed until you change them from another device and add two step sign in. Copy documents back by hand rather than restoring an image made after the first contact.

Will Fortect remove andbake.cam?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For andbake.cam, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove armoniamiddleeast.ae: a site that served fake Chrome installers for Windows, and what to do

armoniamiddleeast.ae is a website that URLhaus lists for three Windows malware downloads named ChromeSetup.exe, Chrome.exe and google.exe, reported on 24 September 2026. They pretend to be Google Chrome installers....TRHigh riskUgnius Kiguolis ·

Remove H1B scam: how fake H-1B job offers and visa fee demands work, and what to do

An H1B scam is a fake job or visa offer that promises H-1B sponsorship and then asks the worker to pay a fee, send identity papers or both. A real employer pays the H-1B filing costs, so stop paying, check the...TRHigh riskUgnius Kiguolis ·

Remove Iplogger.org

Iplogger.org is a misleading URL that may be misused by malware for tracking users' IP addresses Iplogger.org or Iplogger.com is a website that allows users to track people's IP addresses byTrojansHigh riskJake Doevan ·

Remove astroliper.ac: a botnet file server for Linux machines entered through SSH, and what to do

astroliper.ac is a web address that URLhaus lists eleven times for nodewatchd, one Linux program built for eleven processor types and tagged ssh: the kind of file botnets put on servers, routers and boards after...TRHigh riskUgnius Kiguolis ·

Questions and experiences: andbake.cam (XWorm, stego PNG files)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,457 members already hereReading, writing, commenting and voting. 0 verified · 182 joined this year