NeoExpressRAT is a custom backdoor associated with the Iranian state-linked threat actor commonly tracked as Lemon Sandstorm, also known as Parisite, Pioneer Kitten, and Fox Kitten. It was observed in a sustained espionage and strategic prepositioning campaign against Middle Eastern critical infrastructure, particularly energy and other high-value infrastructure environments. The malware formed part of a broader intrusion set that also included HanifNet, HXLibrary, Havoc, MeshCentral, and SystemBC.
NeoExpressRAT was deployed during the later stages of the intrusion to maintain long-term access inside the victim environment. It was executed through a scheduled-task-driven DLL proxy execution chain that abused a legitimate Windows binary to load malicious components. Reporting describes it as a Golang-based implant and characterizes it as a novel backdoor. Its loader chain used staged components and external content-hosting services to retrieve payload material before establishing command-and-control communications.
The malware’s primary role was persistent remote access and post-compromise control. It communicated with attacker infrastructure over HTTPS and likely retrieved configuration data from its command-and-control server. Available reporting also assesses that it likely supported Discord-related follow-on communications. In operational context, NeoExpressRAT was used after the adversary had already obtained access through stolen VPN credentials and extensive credential theft, and while the actor was conducting lateral movement, proxy chaining across segmented networks, reconnaissance of restricted infrastructure segments, and targeted data collection.
NeoExpressRAT is linked to a long-dwell campaign focused on espionage rather than immediate disruptive or destructive effects. The surrounding operations involved credential harvesting, mailbox collection, movement across Windows and Linux systems, and attempts to reach OT-adjacent environments, although no confirmed OT disruption was reported. NeoExpressRAT therefore appears to be one element of a tailored access-and-persistence ecosystem used to sustain covert footholds in strategically important networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Scheduled task executes the legitimate Windows binary ‘format.com’ with command line arguments ‘c: /fs:FXSEXT’. This results in proxy execution of a dll ‘UFXSEXT.dll’ which leads to the execution of NeoExpressRAT malware. | FGIR identified that on 04 August 2024, the adversary deployed another series of loaders, resulting in the final payload execution of a novel backdoor FortiGuard tracks as NeoExpressRAT.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Scheduled task executes the legitimate Windows binary ‘format.com’ with command line arguments ‘c: /fs:FXSEXT’. This results in proxy execution of a dll ‘UFXSEXT.dll’ which leads to the execution of NeoExpressRAT malware. | the task name was ‘SpaceStorageTask’... includes using a LOLbin execution technique that leverages the legitimate Windows binary ‘format.com’ for proxy execution (T1218).
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan in Parisite’s custom malware ecosystem used during sustained intrusions into energy and infrastructure sectors.
Remote access trojan/backdoor used for persistent remote control during long-term access operations.
Backdoor/RAT that retrieves configuration from C2 and likely uses Discord for follow-on communications.
A Golang-based backdoor/RAT with hardcoded C2 communication, used to maintain persistence and support command execution, file operations, and system discovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.