Last seven days
- First activity
- Aug 7, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2
- Host form
- 1 IP / 1 hostnames
XenoRAT is an open-source .NET remote access trojan used by multiple threat actors for persistent remote control, surveillance, and post-exploitation on Windows systems.
Profile source: Mallory opens in a new tabXenoRAT
XenoRAT is an open-source .NET remote access trojan used by multiple threat actors for persistent remote control, surveillance, and post-exploitation on Windows systems. It has appeared both as a stock payload and as the basis for customized derivatives such as MoonPeak. Reported intrusion chains show XenoRAT delivered primarily through spear-phishing lures, commonly using malicious LNK files, ZIP archives, PowerShell, HTA content, and payload staging from public developer or cloud platforms such as GitHub. Observed operators have used decoy documents, fileless or in-memory loaders, scheduled tasks, and registry-based autoruns to reduce user suspicion and maintain access.
Documented campaigns link XenoRAT to espionage and financially motivated operations. It has been deployed in activity targeting South Korean organizations, including diplomatic and gaming-sector victims, and in SideCopy operations against Afghan government and finance networks. Kimsuky-aligned and other DPRK-linked activity has also used XenoRAT or MoonPeak-derived variants, while additional campaigns have delivered XenoRAT alongside other commodity RATs through modular loaders.
Observed and reported functionality includes long-term remote access, command execution, file operations, system reconnaissance, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, proxying or SOCKS tunneling, and self-uninstall capability. Some campaigns also used XenoRAT-related infection chains to exfiltrate system information. Delivery and execution frequently rely on defense-evasion measures such as obfuscation, anti-analysis checks, reflective or in-memory loading, and persistence disguised as legitimate software updates.
C2 tracking
Derp observations, rolling seven-day window
Samples
16b5474f30ebd15e96ae71cdca120127c1c2212c2d04386dad168be90a5b1cb7 2c0bfd9f625ee02087858edfa79c243c2fd1c75cd1c45a579970273df8502e56 6be7a1d1f1b694636c0445da41aefdd1841abb76e6b20c174c3721859fb4ef0f abe4ced27b1c19ac49269c469d30855efa54b58819a6a4ee774eba7e367a33b3 da456682afc04a8ea4976611bc3ff2ef1962dd239aa524580520bfecef92b80a 45f245b964952e7ab59f50597ba1458ea8a3dfe42f0bc9a12696af02a810fbac Reported operators
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
The group’s arsenal includes proprietary malware such as PebbleDash, BabyShark, AppleSeed, and RandomQuery, as well as open-source RATs like xRAT, XenoRAT, and TutRAT.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
…LUMMASTEALER, XENORAT, SECTOPRAT…
“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”
Exploited software
MITRE ATT&CK
Reporting
AhnLab published a June 2026 threat trend report summarizing advanced persistent threat activity detected in South Korea through its monitoring infrastructure. The report compiles classifications and statistics for APT attacks observed in the country and outlines the capabilities associated with each attack type, providing a snapshot of the domestic threat landscape. The available references indicate the report is a high-level assessment rather than a detailed disclosure of specific indicators, malware samples, or actor attribution in the excerpted material. Even so, the publication highlights continued monitoring of targeted intrusion activity in South Korea and frames the findings as part of AhnLab ASEC’s ongoing reporting on regional APT operations.
Hauri reported a multi-stage MoonPeak intrusion targeting the gaming industry that began with a malicious Windows shortcut (.LNK) file disguised as a game character design document. When opened, the file launched a PowerShell-based infection chain that checked for analysis environments, gathered host information, and created aes.js at runtime to steal browser cookies, which were then used in command-and-control communications. The campaign used social engineering tailored to game-development workflows, indicating deliberate targeting of gaming-sector personnel. The malware established persistence through Windows Task Scheduler, downloaded additional payloads, and restored a later-stage component from GZIP data masquerading as an RTF file. Hauri identified the final payload as MoonPeak, a variant based on XenoRAT, citing its asynchronous socket communications with its C2 server and reuse of a mutex string previously observed in MoonPeak cases. A related social media post amplified the report and highlighted the same core elements: MoonPeak, XenoRAT, and malicious LNK delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.