XenoRAT is an open-source .NET remote access trojan used by multiple threat actors for persistent remote control, surveillance, and post-exploitation on Windows systems. It has appeared both as a stock payload and as the basis for customized derivatives such as MoonPeak. Reported intrusion chains show XenoRAT delivered primarily through spear-phishing lures, commonly using malicious LNK files, ZIP archives, PowerShell, HTA content, and payload staging from public developer or cloud platforms such as GitHub. Observed operators have used decoy documents, fileless or in-memory loaders, scheduled tasks, and registry-based autoruns to reduce user suspicion and maintain access.
Documented campaigns link XenoRAT to espionage and financially motivated operations. It has been deployed in activity targeting South Korean organizations, including diplomatic and gaming-sector victims, and in SideCopy operations against Afghan government and finance networks. Kimsuky-aligned and other DPRK-linked activity has also used XenoRAT or MoonPeak-derived variants, while additional campaigns have delivered XenoRAT alongside other commodity RATs through modular loaders.
Observed and reported functionality includes long-term remote access, command execution, file operations, system reconnaissance, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, proxying or SOCKS tunneling, and self-uninstall capability. Some campaigns also used XenoRAT-related infection chains to exfiltrate system information. Delivery and execution frequently rely on defense-evasion measures such as obfuscation, anti-analysis checks, reflective or in-memory loading, and persistence disguised as legitimate software updates.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
The group’s arsenal includes proprietary malware such as PebbleDash, BabyShark, AppleSeed, and RandomQuery, as well as open-source RATs like xRAT, XenoRAT, and TutRAT.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
the operators attempted to use our models to engage in malware and command-and-control (C2) development
That loader DLL downloaded an encoded, GZIP-compressed blob from attacker-controlled URLs and unpacked it entirely in memory.
The loader script implements a custom Base64 decoding routine to hide its downstream modules.
Instead of dropping a binary immediately, the shortcut covertly launches the native Windows command tool mshta.exe. This legitimate system binary fetches an externally hosted hypertext application file from a compromised domain.
Subsequently, once fully initialized, the backdoor implants open a persistent command channel back to the malicious operators. This outgoing data stream targets a dedicated server node located at internet protocol destination 185.235.137.106.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan/backdoor distributed via spear phishing chains, using scheduled-task persistence and decoy files/scripts to establish remote control over infected systems.
Scheduled-task-based malware delivery that masquerades as a browser update and deploys XenoRAT for remote access/backdoor capability.
XenoRAT is referenced as the basis for the final MoonPeak variant loaded in the infection chain.
XenoRAT is mentioned as a related malware/tool in the context of the MoonPeak infection case.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.