XDealer, also known as DinodasRAT, is a remote-access backdoor used in cyberespionage operations. It has Windows and Linux variants and is deployed with associated loader, installer, and stealer components. Earth Krahang has used XDealer since at least 2023, increasingly replacing its earlier RESHELL backdoor, against government organizations and telecommunications, postal, and media entities, particularly in Southeast Asia. Observed delivery includes spear-phishing archives containing shortcut files that execute XDealer while displaying decoy documents, as well as deployment from web shells on compromised public-facing servers. XDealer has also been associated with activity attributed to LuoYu.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Earth Krahang is known to conduct spear-phishing attacks and exploiting vulnerable public-facing servers such as Oracle Web Applications Desktop Integrator CVE-2022-21587 (CVSS 9.8) ... to install backdoors such as Cobalt Strike, RESHELL, and XDealer. | Earth Krahang exploits vulnerable public-facing servers "to install backdoors such as Cobalt Strike, RESHELL, and XDealer." The IoCs also identify an XDealer loader, installer, stealer module, LNK/VBS files, and a Linux version.
Earth Krahang is known to conduct spear-phishing attacks and exploiting vulnerable public-facing servers such as ... OpenFire CVE-2023-32315 (CVSS 7.5) to install backdoors such as Cobalt Strike, RESHELL, and XDealer. | Earth Krahang exploits vulnerable public-facing servers "to install backdoors such as Cobalt Strike, RESHELL, and XDealer." The IoCs also identify an XDealer loader, installer, stealer module, LNK/VBS files, and a Linux version.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earth Krahang exploits vulnerable public-facing servers "to install backdoors such as Cobalt Strike, RESHELL, and XDealer." The IoCs also identify an XDealer loader, installer, stealer module, LNK/VBS files, and a Linux version.
Since 2023, the Earth Krahang shifted to another backdoor (named XDealer by TeamT5 and DinodasRAT by ESET). Compared to RESHELL, XDealer provides more comprehensive backdoor capabilities.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Earth Krahang abuses the trust between governments to conduct their attacks. We found that the group frequently uses compromised government webservers to host their backdoors and send download links to other government entities via spear phishing emails.
In one case, the actor used a compromised mailbox from a government entity to send a malicious attachment to 796 email addresses belonging to the same entity.
The advisory identifies XDealer, RESHELL, Cobalt Strike, PlugX, and ShadowPad among campaign malware.
Earth Krahang exploited Oracle Web Applications Desktop Integrator CVE-2022-21587 and OpenFire CVE-2023-32315.
The persistence process is quite extensive and covers multiple Ubuntu versions and RedHat distributions... achieves persistence by one of the following methods: Method 1 (Ubuntu) – rc.local enabled via systemd... Method 2 (Red Hat) – init.d script... Method 3 (Red Hat) – rc.local
The persistence process is quite extensive and covers multiple Ubuntu versions and RedHat distributions... achieves persistence by one of the following methods: Method 1 (Ubuntu) – rc.local enabled via systemd... Method 2 (Red Hat) – init.d script... Method 3 (Red Hat) – rc.local
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Xdealer is a backdoor malware deployed via spear-phishing campaigns by the Earth Krahang APT group. It is used to gain persistent access to victim systems, enabling espionage and further malicious activity.
A more feature-rich backdoor used on both Windows and Linux. Early packages included an installer, XDealer DLL, stealer module DLL, ID file, and LNK/loader. The stealer module can take screenshots, steal clipboard data, and log keystrokes.
Malware newly used by LuoYu since JSAC2021 (no further technical detail provided in the content).
A backdoor deployed by Earth Krahang, with associated loader, installer, credential-stealing module, and Windows and Linux components.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.