xRAT is a name used for multiple remote access trojan implementations, most commonly a Windows RAT derived from the open-source QuasarRAT codebase and, separately, an Android surveillance trojan associated with the older mRAT/Xsser family. In Windows intrusions, xRAT has been used by several espionage actors, including Kimsuky, and has also appeared in campaigns linked to A41APT/APT10-related activity and Hellsing tooling references. The Windows variant provides remote control of infected hosts and has been observed supporting command execution, file transfer, system information collection, and keylogging. Delivery has included spearphishing chains using malicious shortcut files and script loaders, dedicated installers, DLL side-loading frameworks, and socially engineered downloads such as fake software or adult-game lures distributed through Korean file-sharing services. Recent observed Windows delivery chains have used process hollowing or injection into legitimate processes and defense-evasion measures such as disabling Windows event tracing, packing loaders, and using encrypted payload stages. Kimsuky-associated operations have used xRAT alongside other malware such as Amadey, RftRAT, AppleSeed, PebbleDash, and Gold Dragon, primarily against South Korean targets in government, defense, media, academia, and related sectors.
A distinct Android xRAT variant functions as a mobile surveillance trojan with extensive collection and remote-control capabilities. It can harvest browser history, SMS messages, contacts, call logs, geolocation, SIM and device metadata, installed application lists, email-related data, Wi-Fi credentials, and content from applications such as QQ and WeChat. It also supports remote shell access, file upload and download, audio recording, phone-call abuse, root-command execution on compromised devices, and destructive actions including broad file deletion and device wiping. This Android branch includes anti-analysis and anti-detection features, operator alerts when security software is present, and a remotely triggered self-uninstall or suicide capability. Reporting has linked it to infrastructure overlaps with Windows malware and assessed it as part of multi-platform targeting, including activity affecting political targets such as Hong Kong pro-democracy circles.
Because the xRAT name is reused across unrelated or loosely related malware contexts, attribution and technical characterization must be scoped carefully to the specific platform and campaign. The strongest common denominator is that xRAT denotes a remote access trojan used for espionage-oriented post-compromise control, information theft, and follow-on payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
XRat is a RAT malware developed in .NET and was created based on QuasarRAT published on GitHub.
During our investigation we’ve observed the Hellsing APT using both the “Xweber” and “msger” backdoors in their attacks, as well as other tools named “xrat”, “clare”, “irene” and “xKat”.
2-4. xRAT ... VERSION 2.0.0.0 ... HOSTS 45.138.157.83:443; ... The payload is xRAT.
该组织擅长对目标实施鱼叉攻击和水坑攻击,植入修改后的ZXShell、Poison Ivy、XRAT商业木马,并使用动态域名作为其控制基础设施。
30 distinct techniques documented for this family, organized by ATT&CK tactic.
该组织擅长对目标实施鱼叉攻击和水坑攻击,植入修改后的ZXShell、Poison Ivy、XRAT商业木马,并使用动态域名作为其控制基础设施。
Six malicious packages on PyPI, the Python Package Index, were found installing information-stealing and RAT (remote access trojan) malware... The six malicious packages that Phylum detected are the following: pyrologin, easytimestamp, discorder, discord-dev, style.py, pythonstyles.
Ht.dll references this information to read and decrypt the encrypted file before injecting it into a legitimate process... Amadey... goes through svchost.exe before being injected into the iexplore.exe process and run.
Injection method is same as the method used by the original Gold Dragon (behavior of process hollowing on iexplore.exe, svchost.exe,etc.) ... Once cp1093.exe is executed, it copies a normal powershell process (powershell_ise.exe) to the “C:\ProgramData\”path and executes xRAT via process hollowing technique.
While these malware are all packed with VMP when in distribution, recently, Amadey and RftRAT variants created with AutoIt have been used... This method seems to be for the purpose of bypassing security products.
Ht.dll references this information to read and decrypt the encrypted file before injecting it into a legitimate process... Amadey... goes through svchost.exe before being injected into the iexplore.exe process and run.
Injection method is same as the method used by the original Gold Dragon (behavior of process hollowing on iexplore.exe, svchost.exe,etc.) ... Once cp1093.exe is executed, it copies a normal powershell process (powershell_ise.exe) to the “C:\ProgramData\”path and executes xRAT via process hollowing technique.
When triggered, xRAT will clean out its installation directory before issuing a package manager command to uninstall itself.
xRAT contains a robust file deletion module, capable of removing large portions of a device or attacker-specified files.
Decrypt multiple PEs and shellcodes sequentially in multiple stages. Multiple algorithms are used for decryption. Finally, the payload is executed in memory.
The developers behind xRAT created an alert system, flagging to the malware operator if any of the following antivirus applications are present on a compromised device.
Samples from both mRAT and xRAT families have an almost identical code structure, make use of the same decryption key, share certain heuristics and naming conventions, and interestingly contain anti-debugging techniques that cause the a frequently-used malware researcher tool, the dex2jar decompiler, to crash.
The Flask app used by the attackers, also known as 'xrat,' can steal the victim's username and IP address...
List all files and directories on external storage List the contents of attacker specified directories Automatically retrieve files that are of an attacker specified type that are between a minimum and maximum size Search external storage for a file with a specific MD5 hash and, if identified, retrieve it
The developers behind xRAT created an alert system, flagging to the malware operator if any of the following antivirus applications are present on a compromised device.
Samples from both mRAT and xRAT families have an almost identical code structure, make use of the same decryption key, share certain heuristics and naming conventions, and interestingly contain anti-debugging techniques that cause the a frequently-used malware researcher tool, the dex2jar decompiler, to crash.
Listed below are the types of data gathered by xRAT and features that enable it to perform reconnaissance, run remote code, and exfiltrate data from Android devices: Browser history Device metadata ... Text messages Contacts Call logs Data from QQ and WeChat ... Email database and any email account username / passwords ... Installed apps
One of the files in the ZIP, 'server.pyw,' launches four threads... one to start a keystroke logger... The malicious packages attempt to steal sensitive user information stored in browsers, run shell commands, and use keyloggers to steal typed secrets.
The command and control servers for xRAT are also linked to Windows malware, indicating that the malicious actors behind this threat are conducting multi-platform attacks against the PCs and mobile devices of targeted groups.
The script now runs 'cftunnel.py,' also included in the ZIP archive, that is used to install a Cloudflare Tunnel client on the victim's machine... The threat actors use this tunnel to remotely access a remote access trojan running on the infected device... even if a firewall protects that device.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
xRAT (QuasarRAT) is a remote access trojan that enables attackers to collect system information, monitor keystrokes, and transfer files without authorization. It uses sophisticated evasion and persistence techniques, including process injection and disabling Windows event logging, to avoid detection and maintain access.
Remote Access Trojan (RAT) that provides attackers with capabilities such as system information collection, keylogging, file download/upload, and remote control. In this campaign, it is injected into explorer.exe and disables ETW event logging for stealth.
Mobile RAT/spyware family referenced as part of broader targeted surveillance campaigns.
Android-focused remote access trojan/surveillanceware used for intelligence collection. It gathers browser history, device metadata, SMS, contacts, call logs, QQ/WeChat data, Wi-Fi passwords, email data, geolocation, and installed apps; supports remote shell access, file download/upload, directory listing, audio recording, phone calls, root command execution, and destructive deletion/wipe functions; and can uninstall itself via a suicide function to evade detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.