XenoRAT is an open-source .NET remote access trojan publicly available on GitHub and used by multiple threat actors for persistent remote access, surveillance, and post-exploitation. Reported capabilities in the provided content include encrypted TCP command-and-control, dynamic assembly loading, remote command execution, file operations, keylogging, screen capture, clipboard monitoring, webcam and microphone surveillance, SOCKS5 tunneling, self-uninstall, and collection or exfiltration of system information. The malware has been observed delivered through spear-phishing and multi-stage loader chains using malicious LNK files, ZIP archives, PowerShell, HTA, JavaScript, Python loaders, and GitHub- or web-hosted staging infrastructure. Persistence mechanisms directly mentioned include Windows scheduled tasks such as XenoUpdateManager and registry Run key entries including a value named Edgre; one report also noted the mutex clouda, while another observed Xeno_rat_nd8912d and install path %LOCALAPPDATA%\XenoManager. Version 1.8.7 is specifically referenced multiple times as a final payload. In the supplied reporting, XenoRAT was associated with SideCopy/Transparent Tribe/APT36 in Operation XENOFISCAL targeting Afghanistan’s Ministry of Finance and provincial finance officials, with command-and-control at 185.235.137.106 and delivery via compromised Afghan infrastructure including abimj.edu.af. It was also referenced in DPRK-linked activity, including MoonPeak as a customized variant of the XenoRAT codebase, campaigns targeting South Korean users and organizations, and German-language SERPENTINE#CLOUD activity that deployed XenoRAT v1.8.7 with C2 at 176.96.136.182. Additional content ties XenoRAT-type payload delivery to spear-phishing campaigns observed by AhnLab in South Korea and to multi-payload shellcode loaders alongside XWorm and AsyncRAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Although XMRig CoinMiner is installed in the end, XenoRAT and a vulnerability scanner script are also installed.”
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
Seqrite Labs identified a sophisticated SideCopy XenoRAT malware attack focused directly on government networks.
The group’s arsenal includes proprietary malware such as PebbleDash, BabyShark, AppleSeed, and RandomQuery, as well as open-source RATs like xRAT, XenoRAT, and TutRAT.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
While earlier versions spread the XenoRAT malware, the current version focuses on deep surveillance.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
It connects to a hard-coded IP address using encrypted TCP traffic and registers itself through both a Windows Scheduled Task named “XenoUpdateManager” and a Registry Run key.
Type A uses malicious PowerShell commands in an LNK file to connect to an external URL, download additional files... Type H involves an HTML script within a CHM help file that performs PowerShell command execution...
That loader DLL downloaded an encoded, GZIP-compressed blob from attacker-controlled URLs and unpacked it entirely in memory.
Subsequently, the remote web application processes a heavily obfuscated JavaScript payload within the host memory space.
The loader script implements a custom Base64 decoding routine to hide its downstream modules.
This staged approach is commonly used in fileless malware... reconstruct the serialized payload entirely in memory without touching disk.
To ensure a long-term presence, the software establishes automated registry execution keys that masquerade as legitimate Windows applications.
It launches a hidden cmd.exe process with a Base64-decoded command (/C choice /C Y /N /D Y /T 3 & Del) that waits for a few seconds and then deletes the running executable file from disk.
The malware later decompresses and decodes the data to reconstruct the final HTA payload... The routine first decodes the Base64 blob... and utilizes the .NET GZipStream class to restore the original payload buffer.
Instead of dropping a binary immediately, the shortcut covertly launches the native Windows command tool mshta.exe. This legitimate system binary fetches an externally hosted hypertext application file from a compromised domain.
The malware runs a mutex called “clouda” to prevent duplicate instances.
The malware runs a mutex called “clouda” to prevent duplicate instances, and it queries installed antivirus products before reporting back to its operators.
The script then checks whether the .NET Framework version v4.0.30319 is installed by querying the registry path HKLM\SOFTWARE\Microsoft\.NETFramework\v4.0.30319.
Subsequently, once fully initialized, the backdoor implants open a persistent command channel back to the malicious operators. This outgoing data stream targets a dedicated server node located at internet protocol destination 185.235.137.106.
After the shortcut file launched mshta.exe, it pulled an HTML Application payload from abimj.edu.af... The final stage deployed XenoRAT 1.8.7... which established an encrypted connection to a bulletproof server in Frankfurt, Germany.
ConnectAndSetupAsync function is responsible for establishing and initializing a TCP-based command-and-control (C2) connection between the client and the remote server.
Type A uses malicious PowerShell commands in an LNK file to connect to an external URL, download additional files... Type B uses curl.Exe ... to download and execute a malicious HTA file... Type F uses CMD and PowerShell commands within the LNK file to download additional files.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
XenoRAT2
Mentioned as a likely prior RAT family referenced by reused loader/script artifacts, but not the primary payload in this intrusion.
Remote access malware deployed in spear-phishing chains, used for persistence, system information exfiltration, and likely remote control of infected hosts.
An open-source remote access trojan used in a targeted espionage campaign against government networks. It is delivered via spear-phishing, executed through a fileless chain using mshta.exe and obfuscated JavaScript/.NET payload reconstruction in memory, then establishes persistence via registry run keys and opens a command channel to attacker-controlled infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.