Skip to content

Xtreme RAT

Xtreme RAT is a Windows remote access trojan used in targeted intrusion and surveillance operations since at least 2012.

Profile source: Mallory opens in a new tab

Xtreme RAT

Family profile

Xtreme RAT is a Windows remote access trojan used in targeted intrusion and surveillance operations since at least 2012. It has appeared in campaigns against government, defense, and civil-administration entities, as well as activists and opposition figures in the Middle East, including Syria, Israel, and the United Arab Emirates. It has also been observed in broader malicious-document and spam-driven delivery operations. The malware is commonly associated with politically motivated espionage activity and has been referenced alongside other commodity RATs such as DarkComet, BlackShades, Poison Ivy, CyberGate, and njRAT in state-aligned or pro-government targeting.

The malware provides remote control over infected systems and supports post-compromise actions including command execution, information theft, deployment of additional malware, and spread to additional systems. Reporting on incidents involving Xtreme RAT indicates use for intelligence collection and follow-on intrusion activity inside victim environments. Infrastructure associated with Xtreme RAT has been identified by a characteristic network service profile, and the malware has been sufficiently widespread to be included in threat-hunting and C2-discovery tooling.

Observed delivery methods include phishing and spearphishing emails carrying malicious attachments or lures tied to current events, conflict themes, shipping themes, and spoofed trusted senders. Xtreme RAT has also been delivered through malicious Microsoft Word document campaigns built with exploit tooling such as Microsoft Word Intruder, including operations that tracked victim opens and payload downloads. In documented Israeli targeting, attackers used a spoofed security-service themed email to implant Xtreme RAT into defense-related systems. In Syrian targeting, Xtreme RAT was one of several RAT families rotated across campaigns aimed at activists.

Xtreme RAT is best characterized as a commodity RAT repeatedly repurposed for targeted espionage and surveillance. Its operational history shows use by multiple actors rather than a single exclusive operator, including activity suspected to involve Palestinian threat actors and campaigns linked to politically motivated monitoring of dissidents and government-related targets.

Capabilities

  • Exfiltration
  • Lateral Movement
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 17, 2026
Last activity
Sep 23, 2026
Feed role
C2 / Distribution
Host form
0 IP / 81 hostnames

Leading locations

  • US3
  • DE2
  • ES1

Leading providers

  • Amazon.com, Inc.1
  • Cogent Communications, LLC1
  • Hetzner Online GmbH1
  • Hurricane Electric LLC1
  • SEDO GmbH1
  • XTRA TELECOM S.A.1

Infrastructure traits

  • Hosting 4
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Molerats

Operating since 2012, the group's activity has been reported by Norman, Kaspersky, FireEye, and PwC.

Exploited software

Vulnerabilities linked to Xtreme RAT

1 CVEs

MITRE ATT&CK

Xtreme RAT in ATT&CK

18 distinct techniques

Reporting

Research mentioning Xtreme RAT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.