Skip to content

XenoRAT

XenoRAT is an open-source .NET remote access trojan used by multiple threat actors for persistent remote control, surveillance, and post-exploitation on Windows systems.

Profile source: Mallory opens in a new tab

XenoRAT

Family profile

XenoRAT is an open-source .NET remote access trojan used by multiple threat actors for persistent remote control, surveillance, and post-exploitation on Windows systems. It has appeared both as a stock payload and as the basis for customized derivatives such as MoonPeak. Reported intrusion chains show XenoRAT delivered primarily through spear-phishing lures, commonly using malicious LNK files, ZIP archives, PowerShell, HTA content, and payload staging from public developer or cloud platforms such as GitHub. Observed operators have used decoy documents, fileless or in-memory loaders, scheduled tasks, and registry-based autoruns to reduce user suspicion and maintain access.

Documented campaigns link XenoRAT to espionage and financially motivated operations. It has been deployed in activity targeting South Korean organizations, including diplomatic and gaming-sector victims, and in SideCopy operations against Afghan government and finance networks. Kimsuky-aligned and other DPRK-linked activity has also used XenoRAT or MoonPeak-derived variants, while additional campaigns have delivered XenoRAT alongside other commodity RATs through modular loaders.

Observed and reported functionality includes long-term remote access, command execution, file operations, system reconnaissance, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, proxying or SOCKS tunneling, and self-uninstall capability. Some campaigns also used XenoRAT-related infection chains to exfiltrate system information. Delivery and execution frequently rely on defense-evasion measures such as obfuscation, anti-analysis checks, reflective or in-memory loading, and persistence disguised as legitimate software updates.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 7, 2026
Last activity
Aug 8, 2026
Feed role
C2
Host form
1 IP / 1 hostnames

Leading locations

  • HK1
  • RU1

Leading providers

  • HKBN Enterprise Solutions HK Limited1
  • Yandex.Cloud LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
Transparent Tribe

Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.

SideCopy

Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.

Kimsuky

The group’s arsenal includes proprietary malware such as PebbleDash, BabyShark, AppleSeed, and RandomQuery, as well as open-source RATs like xRAT, XenoRAT, and TutRAT.

APT37

While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.

Lazarus

While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.

UAC-0050

…LUMMASTEALER, XENORAT, SECTOPRAT…

LemonDuck

“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”

Exploited software

Vulnerabilities linked to XenoRAT

1 CVEs

MITRE ATT&CK

XenoRAT in ATT&CK

55 distinct techniques

Techniques

55 techniques
T1059 Command and Scripting Interpreter T1071.001 Web Protocols T1566 Phishing T1140 Deobfuscate/Decode Files or Information T1105 Ingress Tool Transfer T1053.005 Scheduled Task T1204.002 Malicious File T1219 Remote Access Tools T1082 System Information Discovery T1497 Virtualization/Sandbox Evasion T1059.001 PowerShell T1095 Non-Application Layer Protocol T1480.002 Mutual Exclusion T1036 Masquerading T1053 Scheduled Task/Job T1539 Steal Web Session Cookie T1620 Reflective Code Loading T1027 Obfuscated Files or Information T1566.001 Spearphishing Attachment T1071 Application Layer Protocol T1059.007 JavaScript T1598 Phishing for Information T1547.001 Registry Run Keys / Startup Folder T1218.005 Mshta T1584 Compromise Infrastructure T1059.005 Visual Basic T1497.001 System Checks T1573 Encrypted Channel T1012 Query Registry T1562.001 Disable or Modify Tools T1123 Audio Capture T1129 Shared Modules T1090.002 External Proxy T1027.011 Fileless Storage T1113 Screen Capture T1564.001 Hidden Files and Directories T1070.004 File Deletion T1056.001 Keylogging T1055 Process Injection T1115 Clipboard Data T1518 Software Discovery T1106 Native API T1125 Video Capture T1059.003 Windows Command Shell T1102.003 One-Way Communication T1059.006 Python T1055.004 Asynchronous Procedure Call T1005 Data from Local System T1112 Modify Registry T1041 Exfiltration Over C2 Channel T1083 File and Directory Discovery T1203 Exploitation for Client Execution T1567 Exfiltration Over Web Service T1057 Process Discovery T1204 User Execution

Reporting

Research mentioning XenoRAT

Jul 25
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

AhnLab published a June 2026 threat trend report summarizing advanced persistent threat activity detected in South Korea through its monitoring infrastructure. The report compiles classifications and statistics for APT attacks observed in the country and outlines the capabilities associated with each attack type, providing a snapshot of the domestic threat landscape. The available references indicate the report is a high-level assessment rather than a detailed disclosure of specific indicators, malware samples, or actor attribution in the excerpted material. Even so, the publication highlights continued monitoring of targeted intrusion activity in South Korea and frames the findings as part of AhnLab ASEC’s ongoing reporting on regional APT operations.

Jul 25
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 24
Malware News

June 2026 Threat Trend Report on APT Attacks (South Korea) - Malware Analysis - Malware Analysis, News and Indicators

Jul 23
Ahnlab Asec

June 2026 Threat Trend Report on APT Attacks (South Korea) - ASEC

Jul 23
Ahnlab Asec

2026년 6월 APT 공격 동향 보고서(국내) - ASEC

Jul 21
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Hauri reported a multi-stage MoonPeak intrusion targeting the gaming industry that began with a malicious Windows shortcut (.LNK) file disguised as a game character design document. When opened, the file launched a PowerShell-based infection chain that checked for analysis environments, gathered host information, and created aes.js at runtime to steal browser cookies, which were then used in command-and-control communications. The campaign used social engineering tailored to game-development workflows, indicating deliberate targeting of gaming-sector personnel. The malware established persistence through Windows Task Scheduler, downloaded additional payloads, and restored a later-stage component from GZIP data masquerading as an RTF file. Hauri identified the final payload as MoonPeak, a variant based on XenoRAT, citing its asynchronous socket communications with its C2 server and reuse of a mutex string previously observed in MoonPeak cases. A related social media post amplified the report and highlighted the same core elements: MoonPeak, XenoRAT, and malicious LNK delivery.

Jul 21
Hauri Co Kr

(주)하우리

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.