Skip to content
Malware family

XenoRAT

XenoRAT is an open-source .NET remote access trojan publicly available on GitHub and used by multiple threat actors for persistent remote access, surveillance, and post-exploitation.

Profile source: Mallory opens in a new tab

XenoRAT

Family profile

XenoRAT is an open-source .NET remote access trojan publicly available on GitHub and used by multiple threat actors for persistent remote access, surveillance, and post-exploitation. Reported capabilities in the provided content include encrypted TCP command-and-control, dynamic assembly loading, remote command execution, file operations, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, SOCKS5 tunneling, self-uninstall, and collection or exfiltration of system information. The malware has been observed delivered through spear-phishing and multi-stage loader chains using malicious LNK files, ZIP archives, PowerShell, HTA, JavaScript, Python loaders, and GitHub- or web-hosted staging infrastructure. Persistence mechanisms directly mentioned include Windows scheduled tasks such as XenoUpdateManager and registry Run key entries including a value named Edgre; one report also noted the mutex clouda, while another observed Xeno_rat_nd8912d and install path %LOCALAPPDATA%\XenoManager\. Version 1.8.7 is specifically referenced multiple times as a final payload. In the supplied reporting, XenoRAT was associated with SideCopy/Transparent Tribe/APT36 in Operation XENOFISCAL targeting Afghanistan’s Ministry of Finance and provincial finance officials, with command-and-control at 185.235.137.106 and delivery via compromised Afghan infrastructure including abimj.edu.af. It was also referenced in DPRK-linked activity, including MoonPeak as a customized variant of the XenoRAT codebase, campaigns targeting South Korean users and organizations, and German-language SERPENTINE#CLOUD activity that deployed XenoRAT v1.8.7 with C2 at 176.96.136.182. Additional content ties XenoRAT-type payload delivery to spear-phishing campaigns observed by AhnLab in South Korea and to multi-payload shellcode loaders alongside XWorm and AsyncRAT.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 19, 2026
Last activity
Jul 22, 2026
Feed role
C2
Host form
1 IP / 2 hostnames

Leading locations

  • US2
  • RU1

Leading providers

  • United Cooperative Services1
  • Wowrack.com1
  • Yandex.Cloud LLC1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
Transparent Tribe

Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.

SideCopy

Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.

Kimsuky

The group’s arsenal includes proprietary malware such as PebbleDash, BabyShark, AppleSeed, and RandomQuery, as well as open-source RATs like xRAT, XenoRAT, and TutRAT.

APT37

While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.

Lazarus

While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.

LemonDuck

“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”

Exploited software

Vulnerabilities linked to XenoRAT

1 CVEs

MITRE ATT&CK

XenoRAT in ATT&CK

53 distinct techniques

Techniques

53 techniques

Reporting

Research mentioning XenoRAT

Jul 21
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

"게임 업계 대상 MoonPeak 감염 사례 분석" published by Hauri. #LNK, #XenoRAT, #MoonPeak

Jul 21
Hauri Co Kr

(주)하우리

최종적으로 XenoRAT 기반 변종으로 알려진 MoonPeak을 로드하는 것을 확인하였다.

Jul 7
Gurucul Threat Research

Millenium: A RAT Rewritten, a Threat Multiplied | Community Portal | Gurucul

XenoRAT2

Jul 6
Levelblue Spiderlabs

From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

While the script references “Xeno”, likely tied to XenoRAT, we believe this script is likely reused with a newer CrySome RAT payload.

Jun 24
Ahnlab Asec

May 2026 Threat Trend Report on APT Attacks (South Korea) - ASEC

Type C uses PowerShell code embedded within the LNK file to create and execute Base64-encoded data in %TEMP%, then downloads decoy files and malicious scripts from a GitHub repository. It creates a Task Scheduler entry to ensure persistence, deploys XenoRAT-type malware, and exfiltrates system information.

Jun 3
Security Online Info

SideCopy XenoRAT Malware Attack Targets Afghanistan

Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.

Jun 1
Cyber Security News

SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry

The final stage deployed XenoRAT 1.8.7, an open-source Remote Access Trojan available on GitHub, which established an encrypted connection to a bulletproof server in Frankfurt, Germany.

May 31
The Record Media

Afghan finance officials targeted by suspected Pakistani cyberespionage campaign | The Record from Recorded Future News

Once opened, the file silently installed XenoRAT, an open-source remote access trojan that allows attackers to maintain long-term access to infected systems.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.