Xeno RAT is an open-source Windows remote access trojan written in C# and publicly available on GitHub, where it includes a builder for generating customized variants. It is widely described as a feature-rich RAT used for surveillance, remote system control, and post-compromise operations. Reported capabilities include remote command execution, file operations, screenshot capture, keystroke logging, clipboard monitoring, webcam and microphone access, system profiling, antivirus discovery, SOCKS5 proxying or tunneling, scheduled-task persistence, self-uninstallation, and support for loading additional modules. Xeno RAT is also notable for integrating hidden virtual network computing (hVNC), enabling covert attacker interaction with a victim system through invisible desktop sessions.
Observed intrusion chains show Xeno RAT delivered through multiple mechanisms, including spearphishing emails with archive attachments containing malicious shortcut files, phishing-driven script execution, and downloader chains that retrieve staged payloads from cloud or code-hosting services. Documented delivery patterns include LNK-to-mshta-to-HTA or JavaScript execution, batch and PowerShell-based staging, abuse of legitimate binaries for execution, DLL sideloading, and process injection. Some campaigns established persistence through scheduled tasks or registry-based masquerading.
The malware has been used by several threat clusters through customized builds rather than only as a commodity tool. Reported users include Pakistan-aligned SideCopy in espionage operations against Afghanistan government finance entities, North Korea-linked Kimsuky in campaigns using GitHub or GitLab-backed staging and command-and-control patterns, and TA584 among broader payload experimentation. Xeno RAT has also appeared in multi-stage criminal delivery chains alongside other RATs. Targeting has included government organizations, diplomatic entities, and cryptocurrency-related victims, with confirmed emphasis on Windows 10 and Windows 11 systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Payload: Customized Xeno RAT ... The final payload is a modified Xeno RAT — a public .NET remote access trojan recompiled with custom changes and pointed at DPRK-controlled C2 servers.
The Payload: Customized Xeno RAT ... The final payload is a modified Xeno RAT — a public .NET remote access trojan recompiled with custom changes and pointed at DPRK-controlled C2 servers.
The malware these steps were in service of, Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
The malware these steps were in service of, Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
The malware these steps were in service of, Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
some of the cyber attacks also leveraging GitHub as a stager for propagating an open-source trojan called Xeno RAT.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence Scheduled tasks ensure continued presence on the system.
Remote Command Execution Full shell and process control over the victim's machine.
The file functions as a downloader, utilizing the Windows command shell to retrieve, extract, and execute the payload from a zip archive, located at the Discord CDN URL.
Upon execution, the LNK file uses mshta.exe to download a remote HTML Application (HTA) from a compromised Afghan education domain, leading to the execution of obfuscated JavaScript.
Two Ways to Get Infected • Direct download — MSI installer signed by shell company "AgilusTech LLC" with a real EV certificate • Microsoft Store — published as a verified app, appearing fully legitimate
Persistence Scheduled tasks ensure continued presence on the system.
ADExplorer64 creates a suspended process named “hh.exe”, writes into its memory (process injection), and then resumes the thread... During the third stage of execution, the hh.exe process generates a suspended colorcpl.exe process and subsequently writes into its memory (process injection).
Heavy Obfuscation ROT ciphers, fragmented strings, and fake code blocks used to defeat static analysis tools.
A couple of loaders followed, and the attackers established persistence via the Windows registry, disguising their task as a Microsoft Edge process.
ADExplorer64 creates a suspended process named “hh.exe”, writes into its memory (process injection), and then resumes the thread... During the third stage of execution, the hh.exe process generates a suspended colorcpl.exe process and subsequently writes into its memory (process injection).
The LNK files used mshta to fetch an HTA payload, which then got decoded in-memory.
The injected process hh.exe employs defensive measures to evade analysis.
The payload only runs if the victim's IP or MAC is on a hardcoded allowlist. Non-matching machines are flagged for later.
let proc = ["ps aux", "ps aux", "tasklist"]; ... postBody.Process = await runCommand(proc[uid]);
The injected process hh.exe employs defensive measures to evade analysis.
Xeno RAT is capable of remote command execution, data exfiltration, network tunneling, and system monitoring, including keystroke logging and screenshot capture.
Xeno RAT, is an open source (OSS) remote stealer, customized in this case with a hardcoded command-and-control (C2) domain hosted by a bulletproof service in Bulgaria.
POSTs JSON to C2 script... Data was sent to a C2 server and an attacker-controlled GitLab repo
Xeno RAT is capable of remote command execution, data exfiltration, network tunneling, and system monitoring, including keystroke logging and screenshot capture.
The malware is equipped to ... support SOCKS5 proxy-based network tunneling ...
Downloads Node.js bundle → unpacks to ~/.nodes • Fetches index.js from C2... Receives base64-encoded response → saves as addon.js
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source remote access trojan and stealer used in this campaign for espionage, customized with a hardcoded C2 domain.
Related:Pakistan Spies on Afghan Finance Ministry With Xeno RAT
Open-source remote access trojan used in a spear-phishing campaign. It enables remote command execution, data exfiltration, network tunneling, and system monitoring, including keystroke logging and screenshot capture.
An open-source remote access trojan used in spear-phishing campaigns. In this campaign it was dropped via a DLL-based loader and established registry-based persistence while enabling remote command handling, DLL module execution, scheduled task launch, antivirus discovery, SOCKS5 tunneling, file operations, keylogging, screenshots, clipboard monitoring, webcam/microphone tracking, persistence removal, and self-uninstall.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.