XenoRAT is an open-source .NET remote access trojan used by multiple threat actors for persistent remote control, surveillance, and post-exploitation on Windows systems. It is publicly available through code-sharing platforms and has been adopted in both cybercrime and espionage operations, including activity linked by researchers to North Korean operators such as Kimsuky and to Pakistan-linked SideCopy campaigns targeting Afghan government entities. Customized derivatives such as MoonPeak are based on the XenoRAT codebase.
Observed intrusion chains commonly deliver XenoRAT through spear-phishing lures, especially malicious shortcut files that invoke PowerShell or mshta-based loaders, as well as through GitHub-hosted payload staging and gaming-themed fake software or Roblox-related tooling aimed at gamers and developers. In several South Korea-focused campaigns, XenoRAT-type payloads were staged from GitHub repositories, accompanied by decoy documents, and persisted through scheduled tasks disguised as browser updates. Other campaigns used ZIP or LNK lures with localized government-themed content to target ministries and provincial offices.
XenoRAT provides long-term remote access and supports broad post-compromise activity. Reported capabilities include system reconnaissance, exfiltration of host information, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, file operations, dynamic loading of additional .NET components, SOCKS5 proxying or tunneling, and general remote command execution. Campaign reporting also shows its use alongside cookie theft or browser-data collection workflows in broader intrusion chains, though those behaviors may be implemented by surrounding loaders or companion modules rather than the core RAT alone.
Persistence mechanisms observed with XenoRAT deployments include Windows scheduled tasks and registry autorun entries. Delivery chains frequently emphasize defense evasion through obfuscated scripts, in-memory execution, reflective loading, staged payload retrieval, and abuse of legitimate Windows binaries and trusted platforms. XenoRAT has also appeared as an encrypted shellcode payload injected into suspended processes by separate loaders.
Victimology spans government, diplomatic, and gaming-related targets. Documented targeting includes South Korean diplomatic and domestic organizations, Afghan Ministry of Finance and provincial government networks, and members of the gaming community exposed to trojanized game tools. Its open-source availability and modular feature set have made it attractive to a diverse set of operators seeking inexpensive but capable Windows remote access malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Introduction XenoRAT, an open-source malware available on GitHub, has been linked to a North Korean hacking group and unnamed threat actors preying on the gaming community.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Indicators that we observed in our casework overlap with a Trellix report that tied similar activity to spear phishing campaigns against South Korean diplomatic missions
The loader script implements a custom Base64 decoding routine to hide its downstream modules.
a GitHub repository portraying its software as scripting engine tools for the popular game Roblox... most disguised as gaming-related executors
Communication between the controller and Xeno RAT clients occurs over TCP sockets... Additionally, C2 servers respond to requests in the same pattern as the one seen below.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source remote access trojan distributed via .gg domains and GitHub repositories disguised as Roblox/gaming tools. The malware communicates with controllers over TCP sockets and advertises capabilities including HVNC, real-time audio surveillance, and a SOCKS5 reverse proxy.
Remote access trojan/backdoor distributed via spear phishing chains, using scheduled-task persistence and decoy files/scripts to establish remote control over infected systems.
Scheduled-task-based malware delivery that masquerades as a browser update and deploys XenoRAT for remote access/backdoor capability.
XenoRAT is referenced as the basis for the final MoonPeak variant loaded in the infection chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.