Last seven days
- First activity
- Aug 31, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2
- Host form
- 3 IP / 1 hostnames
XenoRAT is an open-source Windows remote access trojan (RAT) publicly available through GitHub.
Profile source: Mallory opens in a new tabXenoRAT
XenoRAT is an open-source Windows remote access trojan (RAT) publicly available through GitHub. It provides encrypted TCP-based command-and-control and supports remote command execution, file operations, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, SOCKS5 proxying, dynamic DLL loading, and self-removal. Observed XenoRAT infection chains have collected host and security-product information, established persistence through scheduled tasks and Windows Registry Run entries, and used multi-stage in-memory loading and obfuscated scripts to reduce detection.
XenoRAT has been deployed in targeted spear-phishing operations against South Korean and Afghan government targets. A SideCopy campaign attributed with medium-to-high confidence to the Pakistan-linked cluster used Pashto-language shortcut lures within ZIP archives to target Afghanistan’s Ministry of Finance and provincial finance offices. XenoRAT and its MoonPeak-derived variant have also appeared in South Korea-focused campaigns using malicious shortcut files, PowerShell, decoy documents, and payload retrieval from public code-hosting services. Other distribution activity has impersonated Roblox-related executors and game-development tools to target gamers and developers. Reporting has also linked use of XenoRAT to suspected DPRK-aligned activity, although attribution varies by campaign.
C2 tracking
Derp observations, rolling seven-day window
Samples
e020141bd79e4247118f722aee28ab1d2085e08dae81759febfa878327630812 3cd99b5138b6bba603a2957333827d91f261617cd1ad57b867e94399cc1b3698 c295b8314d3f230d8a37052525f5798416a5a017091ff95983fb399f5bf7f8a6 e65dfe51cd4c2d1f83a84f1ea71c9e64af9f5f23cfdc21ecc1d58a63b6971589 4108407c3ca18e18fc628776f44bf287432d2a4dd362d27f3a147071dd10d32c 69f49e87f1c828f287740f5578b8440b93f92e897071fd618903180f80b9a4e6 c7748592235b286dda7e73a1fdfcc29ed0f251668c15d41b4e43a86a7c73d9bb d4aafdb79133d87c9fbab58def9fd167d45a74da62c0a651b1221af6f211e22e Reported operators
"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom
"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
…LUMMASTEALER, XENORAT, SECTOPRAT…
“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”
Exploited software
MITRE ATT&CK
Reporting
Researchers reconstructed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras, with the largest concentration of affected devices in Ukraine and Russia. The operation was pieced together from an exposed directory on 154.86.119.60 containing the operator’s tooling, logs, source code, and staging files. According to the report, the attackers used three parallel access paths: credential brute forcing on TCP/37777, exploitation of CVE-2021-33044 and CVE-2021-33045, and abuse of Dahua’s P2P cloud relay to reach cameras by serial number. Researchers said the relay path relied on cloud-issued session tokens obtainable through fixed SDK credentials embedded in Dahua clients, enabling unauthenticated access through that channel. The operators also installed a persistent backdoor account, p2pwn / p2password, on 1,923 cameras; the account reportedly survives password changes and, on most firmware, even factory resets, while offline-generated recovery codes could provide additional cloud-level administrative reset capability by serial number. Hunt.io said some CVE labels used in the tooling were incorrect, including a misreference to CVE-2024-39943 and an overbroad use of CVE-2025-31702, and it made no attribution claim for the campaign. The same host also staged a separate UPX-packed Windows payload believed to be SalatStealer and a PowerShell script for Microsoft Defender exclusions. Defenders were urged to treat exposed Dahua cameras as potentially compromised, remove the p2pwn account, rotate credentials, disable P2P where unnecessary, and apply firmware updates covered by Dahua SA-2021-0130.
AhnLab published a June 2026 threat trend report summarizing advanced persistent threat activity detected in South Korea through its monitoring infrastructure. The report compiles classifications and statistics for APT attacks observed in the country and outlines the capabilities associated with each attack type, providing a snapshot of the domestic threat landscape. The available references indicate the report is a high-level assessment rather than a detailed disclosure of specific indicators, malware samples, or actor attribution in the excerpted material. Even so, the publication highlights continued monitoring of targeted intrusion activity in South Korea and frames the findings as part of AhnLab ASEC’s ongoing reporting on regional APT operations.
Hauri reported a multi-stage MoonPeak intrusion targeting the gaming industry that began with a malicious Windows shortcut (.LNK) file disguised as a game character design document. When opened, the file launched a PowerShell-based infection chain that checked for analysis environments, gathered host information, and created aes.js at runtime to steal browser cookies, which were then used in command-and-control communications. The campaign used social engineering tailored to game-development workflows, indicating deliberate targeting of gaming-sector personnel. The malware established persistence through Windows Task Scheduler, downloaded additional payloads, and restored a later-stage component from GZIP data masquerading as an RTF file. Hauri identified the final payload as MoonPeak, a variant based on XenoRAT, citing its asynchronous socket communications with its C2 server and reuse of a mutex string previously observed in MoonPeak cases. A related social media post amplified the report and highlighted the same core elements: MoonPeak, XenoRAT, and malicious LNK delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.