XenoRAT

First seen
2018-03-15 00:00:00
Malware type
rat, keylogger
Family
Malware family
Last IoC activity
2026-07-22 03:55:48
Profile updated
2026-07-07 13:14:22

Targeted industries: professional-services financial-services technology-and-telecommunications

Context

XenoRAT is an open source remote access trojan written in C#. It can monitor user activity including keystrokes, and provide remote control over the compromised system.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Xenorat (yara-rule)

Reports & references

  • Cisco Talos — Moonpeak Malware Infrastructure North Korea (report)
  • seqrite.com — Goodbye Hta Hello Msi New Ttps And Clusters Of An Apt Driven By Multi Platform Attacks (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Xenorat (report)
  • hunt.io — Xenorat Excel Xll Confuserex As Access Method (report)
  • hunt.io — Good Game Gone Bad Xeno Rat Spread Via Gg Domains And Github (report)
  • trellix.com — Dprk Linked Github C2 Espionage Campaign (report)
  • github.com — Xeno Rat (report)
  • axmahr.github.io — Xenorat Detection (report)
  • cyfirma.com — Xeno Rat A New Remote Access Trojan With Advance Capabilities (report)

External references