Skip to content

SeroXen

Family profile

SeroXen is a remote access trojan (RAT). Trend Micro describes it as gaining popularity for its stealth and notes that recent iterations target gamers, enthusiast communities, and organizations. Trend Micro also states that SeroXen incorporates an updated BatCloak engine as its loading mechanism, tying it to heavily obfuscated batch-file execution designed to evade security controls and persistently avoid detection. Supporting reporting on DOSfuscation additionally lists SeroXen among malware families associated with obfuscated Windows batch/CMD scripts, including infection chains where phishing emails deliver ZIP archives containing disguised .lnk shortcut files that launch cmd.exe with obfuscated commands. High-confidence behavior from the provided content therefore links SeroXen to stealth-focused delivery and loading via obfuscated batch/CMD mechanisms and BatCloak-based protection. Mention contexts also associate SeroXen with DarkWatchman RAT, Mélofée, and AlienReverse implants. No specific IOCs for SeroXen itself are provided in the content.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.