Xeno RAT is a freely available, open-source remote access trojan written in C# for Windows. Its operator-side builder supports customized payload generation, and its public codebase has been adapted by both espionage actors and cybercriminals. MoonPeak is a variant associated with the Xeno RAT toolset.
Xeno RAT provides remote command execution, external DLL module execution, file management and transfer, data exfiltration, keylogging, screenshot capture, clipboard monitoring, and webcam and microphone access. Hidden Virtual Network Computing (hVNC) enables operators to interact with an invisible desktop, including launching browsers and command interpreters without displaying their activity to the victim. SOCKS5 reverse proxying supports network tunneling. The malware communicates with operator-controlled servers, receives commands, sends status updates, and can retrieve information about installed antivirus products. It supports scheduled-task and startup persistence, removal of persistence, and self-uninstallation.
Observed delivery mechanisms include phishing and spear-phishing, malicious Windows shortcuts disguised as images or documents, and trojanized applications presented as cryptocurrency trading software. Multistage deployment chains have used DLL sideloading through legitimate signed applications, injection into legitimate Windows processes, in-memory payload loading, obfuscation, and anti-debugging or sandbox checks. Legitimate services, including Discord, GitHub, and GitLab, have been abused for payload hosting, staging, or command-and-control infrastructure.
Xeno RAT has been used in Kimsuky-linked operations and by the initial access broker TA584. Deployments have targeted Afghan government finance bodies, South Korean organizations, and cryptocurrency users. Its availability and customization capabilities allow unrelated actors to deploy distinct versions through different infection chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Во извештај објавен во јуни 2026 година, Seqrite Labs го поврза SideCopy со spear-phishing кампања насочена кон Министерството за финансии на Авганистан, при што бил користен open-source Remote Access Trojan наречен Xeno RAT.
Во извештај објавен во јуни 2026 година, Seqrite Labs го поврза SideCopy со spear-phishing кампања насочена кон Министерството за финансии на Авганистан, при што бил користен open-source Remote Access Trojan наречен Xeno RAT.
The Payload: Customized Xeno RAT ... The final payload is a modified Xeno RAT — a public .NET remote access trojan recompiled with custom changes and pointed at DPRK-controlled C2 servers.
The Payload: Customized Xeno RAT ... The final payload is a modified Xeno RAT — a public .NET remote access trojan recompiled with custom changes and pointed at DPRK-controlled C2 servers.
The malware these steps were in service of, Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
some of the cyber attacks also leveraging GitHub as a stager for propagating an open-source trojan called Xeno RAT.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Remote Command Execution Full shell and process control over the victim's machine.
The file functions as a downloader, utilizing the Windows command shell to retrieve, extract, and execute the payload from a zip archive.
Upon execution, the LNK file uses mshta.exe to download a remote HTML Application (HTA) from a compromised Afghan education domain, leading to the execution of obfuscated JavaScript.
Heavy Obfuscation ROT ciphers, fragmented strings, and fake code blocks used to defeat static analysis tools.
A couple of loaders followed, and the attackers established persistence via the Windows registry, disguising their task as a Microsoft Edge process.
ADExplorer64 creates a suspended process named “hh.exe”, writes into its memory (process injection), and then resumes the thread.
The LNK files used mshta to fetch an HTA payload, which then got decoded in-memory.
The payload only runs if the victim's IP or MAC is on a hardcoded allowlist. Non-matching machines are flagged for later.
Xeno RAT is capable of remote command execution, data exfiltration, network tunneling, and system monitoring, including keystroke logging and screenshot capture.
Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
Xeno RAT is capable of remote command execution, data exfiltration, network tunneling, and system monitoring, including keystroke logging and screenshot capture.
The malware is equipped to ... support SOCKS5 proxy-based network tunneling ...
Downloads Node.js bundle → unpacks to ~/.nodes • Fetches index.js from C2... Receives base64-encoded response → saves as addon.js
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source remote-access trojan cited as having been used by SideCopy in a separate spear-phishing campaign targeting Afghanistan's Ministry of Finance.
Open-source remote-access trojan referenced in connection with a separate SideCopy spear-phishing campaign targeting Afghanistan's Ministry of Finance.
An open-source remote access trojan and stealer used in this campaign for espionage, customized with a hardcoded C2 domain.
Related:Pakistan Spies on Afghan Finance Ministry With Xeno RAT
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.