Operating since 2012, the group's activity has been reported by Norman, Kaspersky, FireEye, and PwC.
Xtreme RAT
Xtreme RAT is a remote access trojan used in targeted intrusion and surveillance campaigns.
Profile source: Mallory opens in a new tabXtreme RAT
Family profile
Xtreme RAT is a remote access trojan used in targeted intrusion and surveillance campaigns. The provided content places its use against Syrian activists, activists and NGOs in Bahrain, Syria, and the United Arab Emirates, and Israeli defense-related targets. Reported delivery methods include phishing emails, malicious attachments and documents, opposition- or conflict-themed bait files, compromised chat or social media accounts, and malicious Word documents generated with Microsoft Word Intruder (MWI). In one Israeli case, Seculert reported that more than 15 computers tied to the Civil Administration and other defense-related organizations were compromised after a spoofed Shin Bet email sent on January 15 referenced Ariel Sharon’s death; the attackers reportedly used Xtreme RAT to issue commands, steal information, load additional trojans, infect additional computers, and access additional databases. Seculert sinkholed the malware to contain that intrusion. The content also notes this was described as the second Xtreme RAT foothold in Israeli defense computers in two years, with code reportedly similar to a 2012 attack from Gaza, though attribution was not confirmed. In Syrian targeting, Xtreme RAT is explicitly reported by EFF and F-Secure as one of the RATs used against activists, alongside DarkComet and others, with lures including conflict-related videos and opposition-themed files. In broader research on Bahrain, Syria, and the UAE, Xtreme RAT is described as one of several commodity RATs used by governments or pro-government actors to eavesdrop on targets, steal information, and unmask anonymous users. The content further links Xtreme RAT to criminal document-exploit campaigns using MWISTAT telemetry: one cluster delivered at least one Xtreme RAT payload, including a sample hosted on 185.10.57.145 configured with the password "1122334455," and another cluster used shipping-themed lure emails and malicious Word attachments to deliver XtremeRAT. SensePost also referenced Xtreme RAT in the context of detecting command-and-control servers with custom Nmap service probes. High-confidence infrastructure and indicators directly mentioned in the content include payload host 185.10.57.145 and the configuration password "1122334455" for one observed sample.
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to Xtreme RAT
1 CVEsMITRE ATT&CK