Xtreme RAT is a remote access trojan used in targeted intrusion and surveillance campaigns. The provided content places its use against Syrian activists, activists and NGOs in Bahrain, Syria, and the United Arab Emirates, and Israeli defense-related targets. Reported delivery methods include phishing emails, malicious attachments and documents, opposition- or conflict-themed bait files, compromised chat or social media accounts, and malicious Word documents generated with Microsoft Word Intruder (MWI). In one Israeli case, Seculert reported that more than 15 computers tied to the Civil Administration and other defense-related organizations were compromised after a spoofed Shin Bet email sent on January 15 referenced Ariel Sharon’s death; the attackers reportedly used Xtreme RAT to issue commands, steal information, load additional trojans, infect additional computers, and access additional databases. Seculert sinkholed the malware to contain that intrusion. The content also notes this was described as the second Xtreme RAT foothold in Israeli defense computers in two years, with code reportedly similar to a 2012 attack from Gaza, though attribution was not confirmed. In Syrian targeting, Xtreme RAT is explicitly reported by EFF and F-Secure as one of the RATs used against activists, alongside DarkComet and others, with lures including conflict-related videos and opposition-themed files. In broader research on Bahrain, Syria, and the UAE, Xtreme RAT is described as one of several commodity RATs used by governments or pro-government actors to eavesdrop on targets, steal information, and unmask anonymous users. The content further links Xtreme RAT to criminal document-exploit campaigns using MWISTAT telemetry: one cluster delivered at least one Xtreme RAT payload, including a sample hosted on 185.10.57.145 configured with the password "1122334455," and another cluster used shipping-themed lure emails and malicious Word attachments to deliver XtremeRAT. SensePost also referenced Xtreme RAT in the context of detecting command-and-control servers with custom Nmap service probes. High-confidence infrastructure and indicators directly mentioned in the content include payload host 185.10.57.145 and the configuration password "1122334455" for one observed sample.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
However, an exploit for Microsoft Word (CVE-2012-0158), which was first associated with APT activity, found its way into the hands of traditional cybercriminals who began using it in spam campaigns in 2013.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Operating since 2012, the group's activity has been reported by Norman, Kaspersky, FireEye, and PwC.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Typically, targets receive either (1) a PE in a .zip or .rar, (2) a file download link, or (3) a link that will trigger a drive-by download.
The malicious Word documents associated with the first cluster are being propagated via spam. The emails are often spoofed to appear to be from legitimate companies and promote topics such as discounts and promotions for holiday shopping.
The attacks we have documented usually involve the use of malicious links or e-mail attachments, designed to obtain information from a device.
We found that the spyware has a modular design, and can download additional modules from a command & control (C&C) server, including password capture...
We found that the spyware has a modular design, and can download additional modules from a command & control (C&C) server, including password capture (from over 20 applications) and recording of screenshots...
תוכנת הסוס הטרויאני מאפשרת... הטענה של תוכנות זדוניות נוספות לרשת
The attacks often include fake or maliciously packaged security tools; intriguing, or ideological, or movement-relevant content... Researchers and security professionals have already profiled many of these RATs, including DarkComet, Blackshades Remote Controller, Xtreme RAT, njRAT, and ShadowTech.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote administration tool used for victim surveillance/remote control; referenced as observed in attacks against Syrian activists.
A remote access trojan delivered as a payload in MWI/MWISTAT campaigns; one sample was configured with password "1122334455" and another campaign used XtremeRAT with the default password.
Remote access trojan used to take control of compromised systems. In this incident it arrived via a spoofed Shin Bet-themed email, bypassed some security controls, enabled the attacker to inject new trojans and commands, steal information, and infect other computers.
Remote access trojan that allows attackers to remotely control infected computers, steal information, load additional malicious programs, access additional data repositories, and spread to other computers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.