Xeno RAT is an open-source Windows remote access trojan written in C# and publicly distributed through GitHub, which has lowered the barrier for both espionage actors and cybercriminals to adopt and customize it. It is compatible with modern Windows systems, including Windows 10 and Windows 11, and includes a builder that enables operators to generate tailored variants for specific campaigns.
The malware provides a broad remote administration and surveillance feature set. Reported capabilities include remote command execution, file operations, data theft, screenshot capture, keystroke logging, clipboard monitoring, webcam and microphone access, SOCKS5 proxying or tunneling, status reporting, startup modification, scheduled-task persistence, module loading, and self-uninstallation. Xeno RAT is also notable for integrating hidden virtual network computing (hVNC) as a standard feature, allowing attackers to interact with an invisible desktop on the victim host for covert browser and PowerShell activity.
Observed intrusion chains delivering Xeno RAT have used multi-stage loaders, malicious shortcut files, ZIP archives, mshta-launched HTA payloads, PowerShell, DLL side-loading or search-order hijacking, and process injection into legitimate Windows processes. Campaigns have also used decoy documents, obfuscated scripts, anti-debugging, sandbox or virtualization evasion, and covert command-and-control traffic to reduce detection. Persistence has been established through scheduled tasks and, in some operations, registry-based mechanisms masquerading as legitimate software.
Xeno RAT has appeared in multiple threat campaigns. Pakistan-aligned SideCopy, associated with Transparent Tribe (APT36), has used customized Xeno RAT in spear-phishing operations targeting Afghanistan government finance entities and other South Asian targets. North Korea-linked activity associated with Kimsuky has also been linked to GitHub-based delivery or command-and-control involving Xeno RAT and the related variant MoonPeak. In addition, cybercriminal delivery operations such as TA584 and multi-stage phishing campaigns have used Xeno RAT alongside other RAT payloads.
The malware is primarily associated with espionage, remote control, and post-compromise access on Windows endpoints, but its open-source availability and modular design make it adaptable across a wide range of intrusion objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware these steps were in service of, Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
The malware these steps were in service of, Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
The malware these steps were in service of, Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
Fortinet notes that earlier iterations of this activity delivered the Xeno RAT malware family. Similar GitHub-based C2 usage for distributing Xeno RAT and its variant MoonPeak was previously reported by ENKI and Trellix, both attributing the activity to Kimsuky.
Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Xeno RAT is capable of remote command execution, data exfiltration, network tunneling, and system monitoring, including keystroke logging and screenshot capture.
The file functions as a downloader, utilizing the Windows command shell to retrieve, extract, and execute the payload from a zip archive, located at the Discord CDN URL.
Upon execution, the LNK file uses mshta.exe to download a remote HTML Application (HTA) from a compromised Afghan education domain, leading to the execution of obfuscated JavaScript.
the malware directly allocates executable memory within the current process using the Windows API VirtualAlloc()... transfers execution to the injected buffer through the CreateThread() API.
ADExplorer64 creates a suspended process named “hh.exe”, writes into its memory (process injection), and then resumes the thread... During the third stage of execution, the hh.exe process generates a suspended colorcpl.exe process and subsequently writes into its memory (process injection).
A couple of loaders followed, and the attackers established persistence via the Windows registry, disguising their task as a Microsoft Edge process.
ADExplorer64 creates a suspended process named “hh.exe”, writes into its memory (process injection), and then resumes the thread... During the third stage of execution, the hh.exe process generates a suspended colorcpl.exe process and subsequently writes into its memory (process injection).
It launches a hidden cmd.exe process with a Base64-decoded command (/C choice /C Y /N /D Y /T 3 & Del) that waits for a few seconds and then deletes the running executable file from disk.
The LNK files used mshta to fetch an HTA payload, which then got decoded in-memory.
The injected process hh.exe employs defensive measures to evade analysis.
The script then checks whether the .NET Framework version v4.0.30319 is installed by querying the registry path HKLM\SOFTWARE\Microsoft\.NETFramework\v4.0.30319.
The injected process hh.exe employs defensive measures to evade analysis.
Xeno RAT is capable of remote command execution, data exfiltration, network tunneling, and system monitoring, including keystroke logging and screenshot capture.
Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
After confirming the nonpresence of Xeno RAT... process starts communicating with the domain “internal-liveapps[.]online”... It sends and receives obfuscated content over the network continuously, exhibiting a pattern resembling to Remote Access Trojan (RAT) activity.
Xeno RAT is capable of remote command execution, data exfiltration, network tunneling, and system monitoring, including keystroke logging and screenshot capture.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source remote access trojan and stealer used in this campaign for espionage, customized with a hardcoded C2 domain.
Related:Pakistan Spies on Afghan Finance Ministry With Xeno RAT
Open-source remote access trojan used in a spear-phishing campaign. It enables remote command execution, data exfiltration, network tunneling, and system monitoring, including keystroke logging and screenshot capture.
An open-source remote access trojan used in spear-phishing campaigns. In this campaign it was dropped via a DLL-based loader and established registry-based persistence while enabling remote command handling, DLL module execution, scheduled task launch, antivirus discovery, SOCKS5 tunneling, file operations, keylogging, screenshots, clipboard monitoring, webcam/microphone tracking, persistence removal, and self-uninstall.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.