Skip to content

xRAT

xRAT is a name used for multiple remote access trojan implementations, most commonly a Windows RAT derived from the open-source QuasarRAT codebase and, separately, an Android surveillance trojan associated with the older mRAT/Xsser family.

xRAT

Family profile

xRAT is a name used for multiple remote access trojan implementations, most commonly a Windows RAT derived from the open-source QuasarRAT codebase and, separately, an Android surveillance trojan associated with the older mRAT/Xsser family. In Windows intrusions, xRAT has been used by several espionage actors, including Kimsuky, and has also appeared in campaigns linked to A41APT/APT10-related activity and Hellsing tooling references. The Windows variant provides remote control of infected hosts and has been observed supporting command execution, file transfer, system information collection, and keylogging. Delivery has included spearphishing chains using malicious shortcut files and script loaders, dedicated installers, DLL side-loading frameworks, and socially engineered downloads such as fake software or adult-game lures distributed through Korean file-sharing services. Recent observed Windows delivery chains have used process hollowing or injection into legitimate processes and defense-evasion measures such as disabling Windows event tracing, packing loaders, and using encrypted payload stages. Kimsuky-associated operations have used xRAT alongside other malware such as Amadey, RftRAT, AppleSeed, PebbleDash, and Gold Dragon, primarily against South Korean targets in government, defense, media, academia, and related sectors.

A distinct Android xRAT variant functions as a mobile surveillance trojan with extensive collection and remote-control capabilities. It can harvest browser history, SMS messages, contacts, call logs, geolocation, SIM and device metadata, installed application lists, email-related data, Wi-Fi credentials, and content from applications such as QQ and WeChat. It also supports remote shell access, file upload and download, audio recording, phone-call abuse, root-command execution on compromised devices, and destructive actions including broad file deletion and device wiping. This Android branch includes anti-analysis and anti-detection features, operator alerts when security software is present, and a remotely triggered self-uninstall or suicide capability. Reporting has linked it to infrastructure overlaps with Windows malware and assessed it as part of multi-platform targeting, including activity affecting political targets such as Hong Kong pro-democracy circles.

Because the xRAT name is reused across unrelated or loosely related malware contexts, attribution and technical characterization must be scoped carefully to the specific platform and campaign. The strongest common denominator is that xRAT denotes a remote access trojan used for espionage-oriented post-compromise control, information theft, and follow-on payload delivery.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection

Samples

Recent samples

2 sandbox samples in the Derp library, newest 2 shown

Reported operators

Threat actors

4 named in public reporting
Kimsuky

XRat is a RAT malware developed in .NET and was created based on QuasarRAT published on GitHub.

Hellsing

During our investigation we’ve observed the Hellsing APT using both the “Xweber” and “msger” backdoors in their attacks, as well as other tools named “xrat”, “clare”, “irene” and “xKat”.

menuPass

2-4. xRAT ... VERSION 2.0.0.0 ... HOSTS 45.138.157.83:443; ... The payload is xRAT.

毒云藤

该组织擅长对目标实施鱼叉攻击和水坑攻击,植入修改后的ZXShell、Poison Ivy、XRAT商业木马,并使用动态域名作为其控制基础设施。

MITRE ATT&CK

xRAT in ATT&CK

30 distinct techniques

Reporting

Research mentioning xRAT