xRAT is an open-source, .NET-based remote access trojan for Windows derived from QuasarRAT and sometimes identified under that name. It enables remote control of compromised systems, system-information collection, keylogging, and unauthorized file transfers, supporting surveillance and information theft.
The North Korea-linked Kimsuky threat actor has deployed xRAT alongside other malware, including Gold Dragon. Kimsuky delivery chains have used spear-phishing emails containing malicious shortcuts that unpack scripts and install remote-control payloads. Observed xRAT deployments use encrypted payloads, packed loaders, and process injection or process hollowing to execute within legitimate Windows processes. xRAT has also appeared as a payload in the A41APT espionage campaign targeting Japanese companies and their overseas branches.
Separate distribution campaigns have delivered xRAT through Korean webhard file-sharing services disguised as adult games. These attacks use multistage loaders to decrypt and inject the payload into a Windows process and patch Event Tracing for Windows functionality to reduce visibility. This distribution targets Windows users through social engineering rather than a demonstrated software vulnerability.
The xRAT name has also been applied to an Android surveillance trojan associated with mRAT/Xsser and a Flask-based Python remote-access application; these should not be conflated with the QuasarRAT-derived Windows malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During our investigation we’ve observed the Hellsing APT using both the “Xweber” and “msger” backdoors in their attacks, as well as other tools named “xrat”, “clare”, “irene” and “xKat”.
2-4. xRAT ... VERSION 2.0.0.0 ... HOSTS 45.138.157.83:443; ... The payload is xRAT.
该组织擅长对目标实施鱼叉攻击和水坑攻击,植入修改后的ZXShell、Poison Ivy、XRAT商业木马,并使用动态域名作为其控制基础设施。
30 distinct techniques documented for this family, organized by ATT&CK tactic.
该组织擅长对目标实施鱼叉攻击和水坑攻击,植入修改后的ZXShell、Poison Ivy、XRAT商业木马,并使用动态域名作为其控制基础设施。
Six malicious packages on PyPI, the Python Package Index, were found installing information-stealing and RAT (remote access trojan) malware... The six malicious packages that Phylum detected are the following: pyrologin, easytimestamp, discorder, discord-dev, style.py, pythonstyles.
Ht.dll references this information to read and decrypt the encrypted file before injecting it into a legitimate process... Amadey... goes through svchost.exe before being injected into the iexplore.exe process and run.
Injection method is same as the method used by the original Gold Dragon (behavior of process hollowing on iexplore.exe, svchost.exe,etc.) ... Once cp1093.exe is executed, it copies a normal powershell process (powershell_ise.exe) to the “C:\ProgramData\”path and executes xRAT via process hollowing technique.
While these malware are all packed with VMP when in distribution, recently, Amadey and RftRAT variants created with AutoIt have been used... This method seems to be for the purpose of bypassing security products.
Ht.dll references this information to read and decrypt the encrypted file before injecting it into a legitimate process... Amadey... goes through svchost.exe before being injected into the iexplore.exe process and run.
Injection method is same as the method used by the original Gold Dragon (behavior of process hollowing on iexplore.exe, svchost.exe,etc.) ... Once cp1093.exe is executed, it copies a normal powershell process (powershell_ise.exe) to the “C:\ProgramData\”path and executes xRAT via process hollowing technique.
When triggered, xRAT will clean out its installation directory before issuing a package manager command to uninstall itself.
xRAT contains a robust file deletion module, capable of removing large portions of a device or attacker-specified files.
Decrypt multiple PEs and shellcodes sequentially in multiple stages. Multiple algorithms are used for decryption. Finally, the payload is executed in memory.
The developers behind xRAT created an alert system, flagging to the malware operator if any of the following antivirus applications are present on a compromised device.
Samples from both mRAT and xRAT families have an almost identical code structure, make use of the same decryption key, share certain heuristics and naming conventions, and interestingly contain anti-debugging techniques that cause the a frequently-used malware researcher tool, the dex2jar decompiler, to crash.
The Flask app used by the attackers, also known as 'xrat,' can steal the victim's username and IP address...
List all files and directories on external storage List the contents of attacker specified directories Automatically retrieve files that are of an attacker specified type that are between a minimum and maximum size Search external storage for a file with a specific MD5 hash and, if identified, retrieve it
The developers behind xRAT created an alert system, flagging to the malware operator if any of the following antivirus applications are present on a compromised device.
Samples from both mRAT and xRAT families have an almost identical code structure, make use of the same decryption key, share certain heuristics and naming conventions, and interestingly contain anti-debugging techniques that cause the a frequently-used malware researcher tool, the dex2jar decompiler, to crash.
Listed below are the types of data gathered by xRAT and features that enable it to perform reconnaissance, run remote code, and exfiltrate data from Android devices: Browser history Device metadata ... Text messages Contacts Call logs Data from QQ and WeChat ... Email database and any email account username / passwords ... Installed apps
One of the files in the ZIP, 'server.pyw,' launches four threads... one to start a keystroke logger... The malicious packages attempt to steal sensitive user information stored in browsers, run shell commands, and use keyloggers to steal typed secrets.
The command and control servers for xRAT are also linked to Windows malware, indicating that the malicious actors behind this threat are conducting multi-platform attacks against the PCs and mobile devices of targeted groups.
The script now runs 'cftunnel.py,' also included in the ZIP archive, that is used to install a Cloudflare Tunnel client on the victim's machine... The threat actors use this tunnel to remotely access a remote access trojan running on the infected device... even if a firewall protects that device.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
xRAT (QuasarRAT) is a remote access trojan that enables attackers to collect system information, monitor keystrokes, and transfer files without authorization. It uses sophisticated evasion and persistence techniques, including process injection and disabling Windows event logging, to avoid detection and maintain access.
Remote Access Trojan (RAT) that provides attackers with capabilities such as system information collection, keylogging, file download/upload, and remote control. In this campaign, it is injected into explorer.exe and disables ETW event logging for stealth.
Mobile RAT/spyware family referenced as part of broader targeted surveillance campaigns.
Android-focused remote access trojan/surveillanceware used for intelligence collection. It gathers browser history, device metadata, SMS, contacts, call logs, QQ/WeChat data, Wi-Fi passwords, email data, geolocation, and installed apps; supports remote shell access, file download/upload, directory listing, audio recording, phone calls, root command execution, and destructive deletion/wipe functions; and can uninstall itself via a suicide function to evade detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.