Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareRansomwareUsed by 4 actors

XenAllPasswordPro

XenAllPasswordPro is a credential-harvesting tool used to extract passwords and other authentication data from system storage. In the provided reporting, it was observed in ransomware and hacktivist intrusions as part of post-compromise credential access activity. Kaspersky-linked reporting states that Crypt Ghouls used XenAllPasswordPro to harvest authentication data from victim systems after gaining access, including in attacks against Russian businesses and government agencies in the mining, energy, finance, retail, and public sectors. The tool was also identified in Cyber Anarchy Squad (C.A.S) operations targeting organizations in Russia and Belarus.

Observed deployment details in Crypt Ghouls intrusions include recurring use of the directory name "allinone2023" and execution from paths such as C:\ProgramData\allinone2023\xenallpasswordpro.exe, C:\ProgramData\dbg\allinone2023\xenallpasswordpro.exe, C:\ProgramData\1c\allinone2023\xenallpasswordpro.exe, and user desktop locations. In some cases, the parent process was wmiprvse.exe, indicating remote execution via WMI; researchers also noted that RDP was sometimes used to execute credential-harvesting tools. Reporting further notes overlaps in use of XenAllPasswordPro across Crypt Ghouls, MorLock, BlackJack, Twelve, Shedding Zmiy/(Ex)Cobalt-linked activity, and C.A.S, suggesting shared tooling or collaboration. High-confidence indicators directly mentioned for this tool include the executable name xenallpasswordpro.exe and the recurring path component allinone2023.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
BlackJack

The attackers employed the XenAllPasswordPro tool to harvest a range of authentication data from the target system.

via securelistsecurelist.com
Twelve

The attackers employed the XenAllPasswordPro tool to harvest a range of authentication data from the target system.

via securelistsecurelist.com
Crypt Ghouls

The attackers employed the XenAllPasswordPro tool to harvest a range of authentication data from the target system.

via securelistsecurelist.com
MorLock

The attackers employed the XenAllPasswordPro tool to harvest a range of authentication data from the target system.

via securelistsecurelist.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Credential Access

1 technique
T1555Credentials from Password StoresEvidence1

The attackers employed the XenAllPasswordPro tool to harvest a range of authentication data from the target system.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.