PythonRatLoader is a Python-based malware loader documented delivering the XWorm remote access trojan on Windows systems. It uses obfuscated Python code and invokes native Windows APIs via Python ctypes to perform APC injection, queuing malicious code for execution inside another process rather than relying on noisier remote-thread creation patterns. This tradecraft aligns with a broader trend toward stealthier process-injection methods intended to reduce detection opportunities during payload execution. The loader’s observed role is as an initial-stage delivery mechanism for XWorm, enabling follow-on remote access and post-compromise activity by injecting the next-stage payload into a target process. Its known behavior supports classification as malware tooling focused on initial access execution and defense evasion through process injection. No high-confidence attribution to a named intrusion set or state sponsor is established from the available facts, and no corroborated victimology, geographic targeting, or industry specialization is directly supported.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.