XTunnel
MITRE ATT&CK: S0117 View on attack.mitre.org
Aliases: Trojan.Shunnael, X-Tunnel, XAPS, Shunnael, xaps, XTunnel
- First seen
- 2013-05-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-07-15 16:45:04
- Profile updated
- 2026-07-07 15:44:47
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:us
Context
XTunnel a VPN-like network proxy tool that can relay traffic between a C2 server and a victim. It was first seen in May 2013 and reportedly used by APT28 during the compromise of the Democratic National Committee.
Detection coverage
- 178 Sigma rules
Malware & tools used
- Credentials In Files (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Windows Command Shell (attack-pattern)
- Network Service Discovery (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Proxy (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Fallback Channels (attack-pattern)
Used by threat actors
- APT28 (threat-actor)
Reports & references
- Broadcom/Symantec — Apt28 Espionage Military Government (report)
- CrowdStrike — Bears Midst Intrusion Democratic National Committee (report)
- netzpolitik.org — Digital Attack On German Parliament Investigative Report On The Hack Of The Left Party Infrastructure In Bundestag (report)
- Kaspersky — 97937 (report)
- Broadcom/Symantec — Apt28 Espionage Military Government (report)
- Kaspersky — 97239 (report)
- secureworks.com — Iron Twilight (report)
- ESET — Eset Sednit Part 2 (report)
- contagiodump.blogspot.de — Russian Apt Apt28 Collection Of Samples (report)
- ESET — Sednit Reloaded Back Trenches (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Xtunnel (report)
- root9b.com — Root9B Follow Up Report Apt28 (report)
- root9b.com — R9B Fsofacy 0 (report)
- Microsoft — Microsoft Security Intelligence Report Volume 19 English (report)
- MITRE ATT&CK — S0117 (report)
- invincea.com — Tunnel Of Gov Dnc Hack And The Russian Xtunnel (report)