XenoRAT is an open-source Windows remote access trojan (RAT) publicly available through GitHub. It provides encrypted TCP-based command-and-control and supports remote command execution, file operations, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, SOCKS5 proxying, dynamic DLL loading, and self-removal. Observed XenoRAT infection chains have collected host and security-product information, established persistence through scheduled tasks and Windows Registry Run entries, and used multi-stage in-memory loading and obfuscated scripts to reduce detection.
XenoRAT has been deployed in targeted spear-phishing operations against South Korean and Afghan government targets. A SideCopy campaign attributed with medium-to-high confidence to the Pakistan-linked cluster used Pashto-language shortcut lures within ZIP archives to target Afghanistan’s Ministry of Finance and provincial finance offices. XenoRAT and its MoonPeak-derived variant have also appeared in South Korea-focused campaigns using malicious shortcut files, PowerShell, decoy documents, and payload retrieval from public code-hosting services. Other distribution activity has impersonated Roblox-related executors and game-development tools to target gamers and developers. Reporting has also linked use of XenoRAT to suspected DPRK-aligned activity, although attribution varies by campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom
"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Indicators that we observed in our casework overlap with a Trellix report that tied similar activity to spear phishing campaigns against South Korean diplomatic missions
The loader script implements a custom Base64 decoding routine to hide its downstream modules.
a GitHub repository portraying its software as scripting engine tools for the popular game Roblox... most disguised as gaming-related executors
Communication between the controller and Xeno RAT clients occurs over TCP sockets... Additionally, C2 servers respond to requests in the same pattern as the one seen below.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
"July 2026 Threat Trend Report on APT Attacks (South Korea)" published by Ahnlab. #Trend, #Phishing, #LNK, #GitHub, #AutoIt, #XenoRAT
"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom
Mentioned as an alternative possibility based only on the original filename xeno.exe, but the report concludes the evidence more strongly favors SalatStealer rather than XenoRAT.
Open-source remote access trojan distributed via .gg domains and GitHub repositories disguised as Roblox/gaming tools. The malware communicates with controllers over TCP sockets and advertises capabilities including HVNC, real-time audio surveillance, and a SOCKS5 reverse proxy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.