XtremeRAT is a publicly available Windows remote access trojan/backdoor that has been repeatedly used in targeted intrusions and broader commodity malware activity. It provides remote control of compromised systems and is commonly grouped with other commodity RATs such as PoisonIvy, DarkComet, BlackShades, NanoCore, BitRAT, and Gh0st RAT. Security reporting has associated its operational use with multiple espionage-focused threat actors, including MoleRATs/Gaza Cybergang and ALUMINUM SARATOGA, particularly in campaigns targeting organizations and individuals in the Middle East and North Africa. It has also appeared in telemetry on targeted malware affecting Southeast Asia.
XtremeRAT is most often delivered through phishing and spearphishing operations, frequently using socially engineered lure documents or attachments to obtain execution on victim systems. In actor tradecraft, it has been used as an openly available implant to establish persistent remote access after initial compromise. Its repeated appearance across state-aligned and politically motivated intrusion sets reflects its value as a low-cost, readily obtainable espionage tool rather than evidence of exclusive attribution to any single operator.
The malware is best characterized as a RAT/backdoor used for post-compromise remote administration and surveillance on Windows hosts. High-confidence reporting in the supplied material supports its use by espionage actors, but does not provide family-specific technical detail beyond its classification and operational deployment patterns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
However, an exploit for Microsoft Word (CVE-2012-0158), which was first associated with APT activity, found its way into the hands of traditional cybercriminals who began using it in spam campaigns in 2013.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
Tools include Molerat Loader, XtremeRAT, SharpStage, DropBook, Spark, Pierogi, PoisonIvy, and many others observed uniquely over the years.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the ALUMINUM SARATOGA threat profile.
A remote access trojan used by Gaza Cybergang in espionage operations.
Publicly available RAT/backdoor tool referenced as part of Molerats' historical toolset.
Remote access trojan mentioned as historical background on tooling used by the actor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.