XenoRAT is an open-source .NET remote access trojan used by multiple threat actors for persistent remote control, surveillance, and post-exploitation on Windows systems. It has appeared both as a final payload and as a codebase for customized derivatives such as MoonPeak. Reported campaigns show XenoRAT delivered through spear-phishing chains, commonly using malicious LNK files, ZIP archives, PowerShell, HTA content, GitHub-hosted stages, and abuse of legitimate Windows utilities such as mshta.exe. In several observed intrusions, operators established persistence through Windows scheduled tasks or user-run persistence mechanisms and used decoy documents to reduce suspicion during installation.
Observed XenoRAT-related campaigns include targeted espionage activity against Afghan government and finance networks attributed with medium-to-high confidence to the Pakistan-linked SideCopy cluster associated with Transparent Tribe/APT36, as well as South Korea-focused spear-phishing activity and German-language commodity malware delivery chains. In these operations, XenoRAT was used to maintain long-term access and support follow-on malicious actions after initial compromise. Customized MoonPeak variants derived from the XenoRAT codebase have also been linked to DPRK-aligned activity, including financially motivated operations against cryptocurrency users and targeted intrusions using trading or gaming-themed lures.
High-confidence reporting indicates XenoRAT supports encrypted command-and-control communications and a broad remote administration feature set. Documented capabilities include host reconnaissance, file operations, command execution, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, SOCKS5 tunneling or proxying, and self-uninstall functionality. Some campaigns also reported exfiltration of system information prior to or alongside XenoRAT deployment. In practical use, XenoRAT functions as a flexible post-compromise platform for espionage, credential and data collection, and sustained operator access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
The group’s arsenal includes proprietary malware such as PebbleDash, BabyShark, AppleSeed, and RandomQuery, as well as open-source RATs like xRAT, XenoRAT, and TutRAT.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
That loader DLL downloaded an encoded, GZIP-compressed blob from attacker-controlled URLs and unpacked it entirely in memory.
The loader script implements a custom Base64 decoding routine to hide its downstream modules.
Instead of dropping a binary immediately, the shortcut covertly launches the native Windows command tool mshta.exe. This legitimate system binary fetches an externally hosted hypertext application file from a compromised domain.
Subsequently, once fully initialized, the backdoor implants open a persistent command channel back to the malicious operators. This outgoing data stream targets a dedicated server node located at internet protocol destination 185.235.137.106.
After the shortcut file launched mshta.exe, it pulled an HTML Application payload from abimj.edu.af... The final stage deployed XenoRAT 1.8.7... which established an encrypted connection to a bulletproof server in Frankfurt, Germany.
Type A는 LNK의 악성 PowerShell 명령으로 외부 URL에 접속해 AutoIt 악성코드를 내려받고... Type B는 curl.exe(윈도우 기본 도구)를 이용해 악성 HTA 파일을 %TEMP%에 다운로드 및 실행했다.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan/backdoor distributed via spear phishing chains, using scheduled-task persistence and decoy files/scripts to establish remote control over infected systems.
Scheduled-task-based malware delivery that masquerades as a browser update and deploys XenoRAT for remote access/backdoor capability.
XenoRAT is referenced as the basis for the final MoonPeak variant loaded in the infection chain.
XenoRAT is mentioned as a related malware/tool in the context of the MoonPeak infection case.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.