Xtreme RAT is a Windows remote access trojan used in targeted intrusion and surveillance operations since at least 2012. It has appeared in campaigns against government, defense, and civil-administration entities, as well as activists and opposition figures in the Middle East, including Syria, Israel, and the United Arab Emirates. It has also been observed in broader malicious-document and spam-driven delivery operations. The malware is commonly associated with politically motivated espionage activity and has been referenced alongside other commodity RATs such as DarkComet, BlackShades, Poison Ivy, CyberGate, and njRAT in state-aligned or pro-government targeting.
The malware provides remote control over infected systems and supports post-compromise actions including command execution, information theft, deployment of additional malware, and spread to additional systems. Reporting on incidents involving Xtreme RAT indicates use for intelligence collection and follow-on intrusion activity inside victim environments. Infrastructure associated with Xtreme RAT has been identified by a characteristic network service profile, and the malware has been sufficiently widespread to be included in threat-hunting and C2-discovery tooling.
Observed delivery methods include phishing and spearphishing emails carrying malicious attachments or lures tied to current events, conflict themes, shipping themes, and spoofed trusted senders. Xtreme RAT has also been delivered through malicious Microsoft Word document campaigns built with exploit tooling such as Microsoft Word Intruder, including operations that tracked victim opens and payload downloads. In documented Israeli targeting, attackers used a spoofed security-service themed email to implant Xtreme RAT into defense-related systems. In Syrian targeting, Xtreme RAT was one of several RAT families rotated across campaigns aimed at activists.
Xtreme RAT is best characterized as a commodity RAT repeatedly repurposed for targeted espionage and surveillance. Its operational history shows use by multiple actors rather than a single exclusive operator, including activity suspected to involve Palestinian threat actors and campaigns linked to politically motivated monitoring of dissidents and government-related targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
However, an exploit for Microsoft Word (CVE-2012-0158), which was first associated with APT activity, found its way into the hands of traditional cybercriminals who began using it in spam campaigns in 2013.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Operating since 2012, the group's activity has been reported by Norman, Kaspersky, FireEye, and PwC.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Typically, targets receive either (1) a PE in a .zip or .rar, (2) a file download link, or (3) a link that will trigger a drive-by download.
The malicious Word documents associated with the first cluster are being propagated via spam. The emails are often spoofed to appear to be from legitimate companies and promote topics such as discounts and promotions for holiday shopping.
The attacks we have documented usually involve the use of malicious links or e-mail attachments, designed to obtain information from a device.
We found that the spyware has a modular design, and can download additional modules from a command & control (C&C) server, including password capture...
We found that the spyware has a modular design, and can download additional modules from a command & control (C&C) server, including password capture (from over 20 applications) and recording of screenshots...
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several malware families seen in AutoIt-based campaigns.
Remote administration tool used for victim surveillance/remote control; referenced as observed in attacks against Syrian activists.
Remote access trojan discussed through distinctive infrastructure traits including a specific banner hash and consistent port 10001 exposure.
[2] http://www.seculert.com/blog/2014/01/xtreme-rat-strikes-israeli-organizations-again.html
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.