Last seven days
- First activity
- Sep 17, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 81 hostnames
Xtreme RAT is a Windows remote access trojan used in targeted intrusion and surveillance operations since at least 2012.
Profile source: Mallory opens in a new tabXtreme RAT
Xtreme RAT is a Windows remote access trojan used in targeted intrusion and surveillance operations since at least 2012. It has appeared in campaigns against government, defense, and civil-administration entities, as well as activists and opposition figures in the Middle East, including Syria, Israel, and the United Arab Emirates. It has also been observed in broader malicious-document and spam-driven delivery operations. The malware is commonly associated with politically motivated espionage activity and has been referenced alongside other commodity RATs such as DarkComet, BlackShades, Poison Ivy, CyberGate, and njRAT in state-aligned or pro-government targeting.
The malware provides remote control over infected systems and supports post-compromise actions including command execution, information theft, deployment of additional malware, and spread to additional systems. Reporting on incidents involving Xtreme RAT indicates use for intelligence collection and follow-on intrusion activity inside victim environments. Infrastructure associated with Xtreme RAT has been identified by a characteristic network service profile, and the malware has been sufficiently widespread to be included in threat-hunting and C2-discovery tooling.
Observed delivery methods include phishing and spearphishing emails carrying malicious attachments or lures tied to current events, conflict themes, shipping themes, and spoofed trusted senders. Xtreme RAT has also been delivered through malicious Microsoft Word document campaigns built with exploit tooling such as Microsoft Word Intruder, including operations that tracked victim opens and payload downloads. In documented Israeli targeting, attackers used a spoofed security-service themed email to implant Xtreme RAT into defense-related systems. In Syrian targeting, Xtreme RAT was one of several RAT families rotated across campaigns aimed at activists.
Xtreme RAT is best characterized as a commodity RAT repeatedly repurposed for targeted espionage and surveillance. Its operational history shows use by multiple actors rather than a single exclusive operator, including activity suspected to involve Palestinian threat actors and campaigns linked to politically motivated monitoring of dissidents and government-related targets.
C2 tracking
Derp observations, rolling seven-day window
Samples
03c624984400f364727f11618a27892495cbea69967b3b11a95f72a08dc14d57 210d2a8f9bb527f54fb9fa6cd149802af71d786cecad7760ad23292abd05ddb4 395e217a68b28e570252bd0b31cb1f343a8a27865b2d19813ab72b15f5906cd2 6e67b2f3f72a9a462d213d8ed0b2a1ac4e564d9832a01dd62124e54f7eef80f6 54173e9d326b8eda1362788dbbed88caa859b7e78063379c414e14f10ae840c0 84dc8adbb4ea45019d07a4cf23fef7d75c15f622ac8dd6693d82da17b46e8355 9ed6ee8892f8f22dedb6a4d199df91742ca3a1a5e1e8a0240b08a301460210b4 5ff8249296cdc12afb5d38c5a7dab5269737a0ba2b50f1173321357375ebefce 82d98c94a04b8312f6fa0d78acef8f7005132fa5c9672690a94258a80e8cccb7 bc75e5067652c0d2397f0707b305aeefa578d50698c5deba27b0f4746552696b Reported operators
Operating since 2012, the group's activity has been reported by Norman, Kaspersky, FireEye, and PwC.
Exploited software
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.