Last seven days
- First activity
- Jul 19, 2026
- Last activity
- Jul 22, 2026
- Feed role
- C2
- Host form
- 1 IP / 2 hostnames
XenoRAT is an open-source .NET remote access trojan publicly available on GitHub and used by multiple threat actors for persistent remote access, surveillance, and post-exploitation.
Profile source: Mallory opens in a new tabXenoRAT
XenoRAT is an open-source .NET remote access trojan publicly available on GitHub and used by multiple threat actors for persistent remote access, surveillance, and post-exploitation. Reported capabilities in the provided content include encrypted TCP command-and-control, dynamic assembly loading, remote command execution, file operations, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, SOCKS5 tunneling, self-uninstall, and collection or exfiltration of system information. The malware has been observed delivered through spear-phishing and multi-stage loader chains using malicious LNK files, ZIP archives, PowerShell, HTA, JavaScript, Python loaders, and GitHub- or web-hosted staging infrastructure. Persistence mechanisms directly mentioned include Windows scheduled tasks such as XenoUpdateManager and registry Run key entries including a value named Edgre; one report also noted the mutex clouda, while another observed Xeno_rat_nd8912d and install path %LOCALAPPDATA%\XenoManager\. Version 1.8.7 is specifically referenced multiple times as a final payload. In the supplied reporting, XenoRAT was associated with SideCopy/Transparent Tribe/APT36 in Operation XENOFISCAL targeting Afghanistan’s Ministry of Finance and provincial finance officials, with command-and-control at 185.235.137.106 and delivery via compromised Afghan infrastructure including abimj.edu.af. It was also referenced in DPRK-linked activity, including MoonPeak as a customized variant of the XenoRAT codebase, campaigns targeting South Korean users and organizations, and German-language SERPENTINE#CLOUD activity that deployed XenoRAT v1.8.7 with C2 at 176.96.136.182. Additional content ties XenoRAT-type payload delivery to spear-phishing campaigns observed by AhnLab in South Korea and to multi-payload shellcode loaders alongside XWorm and AsyncRAT.
C2 tracking
Derp observations, rolling seven-day window
Samples
23ac180f55e1317de214e450fcb399aa687ca1bd3252a5b7e112bbaf49d0bf42 29344500383487701f9a61e7bb136c01eff46954993c39071bf04d4df3d207e5 36ae1fafc5722b0e3ea0b92ed37d3debf04983da0569e9bc8cfd5488e49a279d 3892c0d5b4d02641c6381904b38950246dd66c58738be1411d46d671e7b7cab1 bc69d5f3877ffb4bc65b9d314d04817c84ee86fc159923337853968000270d5b 0b48a2e61fc087a902087e458945d8f4e095c23e59d170cdfddf5170670e4f62 80246e45911dacf16bd729037fb08d25e2aa38b786a10c7c7bdc7777cf2a1518 622ce6b9c88da24478fdce6e6c09bd3a063164af06dfe0c96b18e795ff76746e Reported operators
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
The group’s arsenal includes proprietary malware such as PebbleDash, BabyShark, AppleSeed, and RandomQuery, as well as open-source RATs like xRAT, XenoRAT, and TutRAT.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
…LUMMASTEALER, XENORAT, SECTOPRAT…
“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”
Exploited software
MITRE ATT&CK
Reporting
"게임 업계 대상 MoonPeak 감염 사례 분석" published by Hauri. #LNK, #XenoRAT, #MoonPeak
최종적으로 XenoRAT 기반 변종으로 알려진 MoonPeak을 로드하는 것을 확인하였다.
XenoRAT2
While the script references “Xeno”, likely tied to XenoRAT, we believe this script is likely reused with a newer CrySome RAT payload.
Type C uses PowerShell code embedded within the LNK file to create and execute Base64-encoded data in %TEMP%, then downloads decoy files and malicious scripts from a GitHub repository. It creates a Task Scheduler entry to ensure persistence, deploys XenoRAT-type malware, and exfiltrates system information.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
The final stage deployed XenoRAT 1.8.7, an open-source Remote Access Trojan available on GitHub, which established an encrypted connection to a bulletproof server in Frankfurt, Germany.
Once opened, the file silently installed XenoRAT, an open-source remote access trojan that allows attackers to maintain long-term access to infected systems.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.