Skip to content

XenoRAT

XenoRAT is an open-source Windows remote access trojan (RAT) publicly available through GitHub.

Profile source: Mallory opens in a new tab

XenoRAT

Family profile

XenoRAT is an open-source Windows remote access trojan (RAT) publicly available through GitHub. It provides encrypted TCP-based command-and-control and supports remote command execution, file operations, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, SOCKS5 proxying, dynamic DLL loading, and self-removal. Observed XenoRAT infection chains have collected host and security-product information, established persistence through scheduled tasks and Windows Registry Run entries, and used multi-stage in-memory loading and obfuscated scripts to reduce detection.

XenoRAT has been deployed in targeted spear-phishing operations against South Korean and Afghan government targets. A SideCopy campaign attributed with medium-to-high confidence to the Pakistan-linked cluster used Pashto-language shortcut lures within ZIP archives to target Afghanistan’s Ministry of Finance and provincial finance offices. XenoRAT and its MoonPeak-derived variant have also appeared in South Korea-focused campaigns using malicious shortcut files, PowerShell, decoy documents, and payload retrieval from public code-hosting services. Other distribution activity has impersonated Roblox-related executors and game-development tools to target gamers and developers. Reporting has also linked use of XenoRAT to suspected DPRK-aligned activity, although attribution varies by campaign.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 31, 2026
Last activity
Sep 2, 2026
Feed role
C2
Host form
3 IP / 1 hostnames

Leading locations

  • CN2
  • US2

Leading providers

  • China Telecom2
  • HostPapa1
  • United States Department of Defense (DoD)1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

8 named in public reporting
Kimsuky

"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom

KONNI

"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom

Transparent Tribe

Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.

SideCopy

Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.

APT37

While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.

Lazarus

While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.

UAC-0050

…LUMMASTEALER, XENORAT, SECTOPRAT…

Lemon Duck

“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”

Exploited software

Vulnerabilities linked to XenoRAT

1 CVEs

MITRE ATT&CK

XenoRAT in ATT&CK

57 distinct techniques

Techniques

57 techniques
T1562 Impair Defenses T1204.002 Malicious File T1566.002 Spearphishing Link T1105 Ingress Tool Transfer T1036 Masquerading T1071 Application Layer Protocol T1059 Command and Scripting Interpreter T1071.001 Web Protocols T1566 Phishing T1140 Deobfuscate/Decode Files or Information T1053.005 Scheduled Task T1219 Remote Access Tools T1082 System Information Discovery T1497 Virtualization/Sandbox Evasion T1059.001 PowerShell T1095 Non-Application Layer Protocol T1480.002 Mutual Exclusion T1053 Scheduled Task/Job T1539 Steal Web Session Cookie T1620 Reflective Code Loading T1027 Obfuscated Files or Information T1566.001 Spearphishing Attachment T1059.007 JavaScript T1598 Phishing for Information T1547.001 Registry Run Keys / Startup Folder T1218.005 Mshta T1584 Compromise Infrastructure T1059.005 Visual Basic T1497.001 System Checks T1573 Encrypted Channel T1012 Query Registry T1562.001 Disable or Modify Tools T1123 Audio Capture T1129 Shared Modules T1090.002 External Proxy T1027.011 Fileless Storage T1113 Screen Capture T1564.001 Hidden Files and Directories T1070.004 File Deletion T1056.001 Keylogging T1055 Process Injection T1115 Clipboard Data T1518 Software Discovery T1106 Native API T1125 Video Capture T1059.003 Windows Command Shell T1102.003 One-Way Communication T1059.006 Python T1055.004 Asynchronous Procedure Call T1005 Data from Local System T1112 Modify Registry T1041 Exfiltration Over C2 Channel T1083 File and Directory Discovery T1203 Exploitation for Client Execution T1567 Exfiltration Over Web Service T1057 Process Discovery T1204 User Execution

Reporting

Research mentioning XenoRAT

Aug 18
Reddit Netsec

🎥 Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and Russia : r/netsec

Researchers reconstructed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras, with the largest concentration of affected devices in Ukraine and Russia. The operation was pieced together from an exposed directory on 154.86.119.60 containing the operator’s tooling, logs, source code, and staging files. According to the report, the attackers used three parallel access paths: credential brute forcing on TCP/37777, exploitation of CVE-2021-33044 and CVE-2021-33045, and abuse of Dahua’s P2P cloud relay to reach cameras by serial number. Researchers said the relay path relied on cloud-issued session tokens obtainable through fixed SDK credentials embedded in Dahua clients, enabling unauthenticated access through that channel. The operators also installed a persistent backdoor account, p2pwn / p2password, on 1,923 cameras; the account reportedly survives password changes and, on most firmware, even factory resets, while offline-generated recovery codes could provide additional cloud-level administrative reset capability by serial number. Hunt.io said some CVE labels used in the tooling were incorrect, including a misreference to CVE-2024-39943 and an overbroad use of CVE-2025-31702, and it made no attribution claim for the campaign. The same host also staged a separate UPX-packed Windows payload believed to be SalatStealer and a PowerShell script for Microsoft Defender exclusions. Defenders were urged to treat exposed Dahua cameras as potentially compromised, remove the p2pwn account, rotate credentials, disable P2P where unnecessary, and apply firmware updates covered by Dahua SA-2021-0130.

Aug 18
Huntio

Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia

Jul 25
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

AhnLab published a June 2026 threat trend report summarizing advanced persistent threat activity detected in South Korea through its monitoring infrastructure. The report compiles classifications and statistics for APT attacks observed in the country and outlines the capabilities associated with each attack type, providing a snapshot of the domestic threat landscape. The available references indicate the report is a high-level assessment rather than a detailed disclosure of specific indicators, malware samples, or actor attribution in the excerpted material. Even so, the publication highlights continued monitoring of targeted intrusion activity in South Korea and frames the findings as part of AhnLab ASEC’s ongoing reporting on regional APT operations.

Jul 25
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 24
Malware News

June 2026 Threat Trend Report on APT Attacks (South Korea) - Malware Analysis - Malware Analysis, News and Indicators

Jul 23
Ahnlab Asec

June 2026 Threat Trend Report on APT Attacks (South Korea) - ASEC

Jul 23
Ahnlab Asec

2026년 6월 APT 공격 동향 보고서(국내) - ASEC

Jul 21
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Hauri reported a multi-stage MoonPeak intrusion targeting the gaming industry that began with a malicious Windows shortcut (.LNK) file disguised as a game character design document. When opened, the file launched a PowerShell-based infection chain that checked for analysis environments, gathered host information, and created aes.js at runtime to steal browser cookies, which were then used in command-and-control communications. The campaign used social engineering tailored to game-development workflows, indicating deliberate targeting of gaming-sector personnel. The malware established persistence through Windows Task Scheduler, downloaded additional payloads, and restored a later-stage component from GZIP data masquerading as an RTF file. Hauri identified the final payload as MoonPeak, a variant based on XenoRAT, citing its asynchronous socket communications with its C2 server and reuse of a mutex string previously observed in MoonPeak cases. A related social media post amplified the report and highlighted the same core elements: MoonPeak, XenoRAT, and malicious LNK delivery.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.