XenoRAT is an open-source remote access trojan developed in C# for Windows, with documented compatibility with Windows 10 and Windows 11. Its modular architecture allows operators to deliver plugin DLLs and load them into memory. It communicates with controllers over TCP using AES-encrypted client-server messages and supports remote command execution, file transfer and execution, process and registry management, interactive screen control, hidden virtual network computing (HVNC), and reverse-proxy tunneling through compromised hosts.
Its surveillance capabilities include online and offline keylogging, screenshot capture, webcam access, and microphone recording. Browser-data collection components extract saved passwords, cookies, browsing history, download records, and saved payment-card information from Chromium-based browsers using Windows DPAPI and AES-GCM decryption. XenoRAT also collects host characteristics, antivirus product information, active-window details, and user idle time. Configurable startup functionality supports persistence, while elevation modules provide UAC-bypass methods. Some distributed samples use packing or obfuscation to hinder analysis. Additional modules can shut down or restart systems and trigger system crashes.
XenoRAT is distributed through phishing and spear-phishing, malicious shortcut files, document-themed lures, malicious downloads, and repositories masquerading as gaming tools. Observed execution chains use PowerShell, decoy documents, and scheduled tasks. Victims include gamers, developers, South Korean diplomatic missions, and Afghan government finance personnel. SideCopy has deployed customized XenoRAT in espionage campaigns targeting Afghanistan, and LemonDuck has installed it alongside XMRig on compromised HTTP File Server systems. MoonPeak is a XenoRAT-based variant associated with North Korea-linked actors. The family's public availability enables use by multiple unrelated operators and does not support exclusive attribution to a single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2024년 5월 HFS의 원격 코드 실행 취약점인 CVE-2024-23692가 공개되었으며 이를 활용할 경우 공격자는 HFS에 명령이 포함된 패킷을 전송하여 HFS가 악성 명령을 실행하도록 할 수 있다.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
최종적으로 설치되는 것은 XMRig 코인 마이너이지만 XenoRAT과 취약점 스캐너 스크립트가 함께 설치되는 것이 특징이다.
"August 2026 Threat Trend Report on APT Attacks (South Korea)" ... #Kimsuky, #Phishing, #LNK, #GitHub, #AutoIt, #XenoRAT, #Hangul, #PubNub
"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
It executes the malicious script in the C:\ProgramData Path and registers a Task Scheduler entry that is disguised as a OneDrive update... Type C... creates a Task Scheduler task... Type D... registers them with the Task Scheduler.
the operators attempted to use our models to engage in malware and command-and-control (C2) development
The Shell plugin provides remote command execution through cmd.exe or powershell.exe on the remote system.
It executes the malicious script in the C:\ProgramData Path and registers a Task Scheduler entry that is disguised as a OneDrive update... Type C... creates a Task Scheduler task... Type D... registers them with the Task Scheduler.
It executes the malicious script in the C:\ProgramData Path and registers a Task Scheduler entry that is disguised as a OneDrive update... Type C... creates a Task Scheduler task... Type D... registers them with the Task Scheduler.
Username — Displays the name of the user account currently logged into the client.
It collects each process's PID, executable path, and description information through WMI (Win32_Process).
The HWID function combines values such as Environment.ProcessorCount, Environment.UserName, Environment.MachineName, Environment.OSVersion, and the total disk capacity.
FileUploader transfers files from the target system to the server in 500,000-byte blocks.
System-wide keyboard input is captured using the SetWindowsHookEx API ... together with the WH_KEYBOARD_LL hook type.
The screenshot is captured by ScreenshotTaker.TakeScreenshot using CopyFromScreen.
Reverse Proxy provides a SOCKS5-like TCP proxy/tunneling mechanism within XenoRAT.
Receives the HVNC DLL sent by the server, and loads it into memory.
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
XenoRAT is identified as a remote-access trojan in the referenced APT-threat report; the post provides no further technical behavior or campaign details.
Remote-access-trojan-type malware distributed by a spear-phishing LNK-file chain. The campaign establishes scheduled-task persistence and exfiltrates system information before distributing XenoRAT-type payloads.
"July 2026 Threat Trend Report on APT Attacks (South Korea)" published by Ahnlab. #Trend, #Phishing, #LNK, #GitHub, #AutoIt, #XenoRAT
"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.