Skip to content

Xtreme RAT

Xtreme RAT is a remote access trojan used in targeted intrusion and surveillance campaigns.

Profile source: Mallory opens in a new tab

Xtreme RAT

Family profile

Xtreme RAT is a remote access trojan used in targeted intrusion and surveillance campaigns. The provided content places its use against Syrian activists, activists and NGOs in Bahrain, Syria, and the United Arab Emirates, and Israeli defense-related targets. Reported delivery methods include phishing emails, malicious attachments and documents, opposition- or conflict-themed bait files, compromised chat or social media accounts, and malicious Word documents generated with Microsoft Word Intruder (MWI). In one Israeli case, Seculert reported that more than 15 computers tied to the Civil Administration and other defense-related organizations were compromised after a spoofed Shin Bet email sent on January 15 referenced Ariel Sharon’s death; the attackers reportedly used Xtreme RAT to issue commands, steal information, load additional trojans, infect additional computers, and access additional databases. Seculert sinkholed the malware to contain that intrusion. The content also notes this was described as the second Xtreme RAT foothold in Israeli defense computers in two years, with code reportedly similar to a 2012 attack from Gaza, though attribution was not confirmed. In Syrian targeting, Xtreme RAT is explicitly reported by EFF and F-Secure as one of the RATs used against activists, alongside DarkComet and others, with lures including conflict-related videos and opposition-themed files. In broader research on Bahrain, Syria, and the UAE, Xtreme RAT is described as one of several commodity RATs used by governments or pro-government actors to eavesdrop on targets, steal information, and unmask anonymous users. The content further links Xtreme RAT to criminal document-exploit campaigns using MWISTAT telemetry: one cluster delivered at least one Xtreme RAT payload, including a sample hosted on 185.10.57.145 configured with the password "1122334455," and another cluster used shipping-themed lure emails and malicious Word attachments to deliver XtremeRAT. SensePost also referenced Xtreme RAT in the context of detecting command-and-control servers with custom Nmap service probes. High-confidence infrastructure and indicators directly mentioned in the content include payload host 185.10.57.145 and the configuration password "1122334455" for one observed sample.

Reported operators

Threat actors

1 named in public reporting
Molerats

Operating since 2012, the group's activity has been reported by Norman, Kaspersky, FireEye, and PwC.

Exploited software

Vulnerabilities linked to Xtreme RAT

1 CVEs

MITRE ATT&CK

Xtreme RAT in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.