XenoRAT
- First seen
- 2018-03-15 00:00:00
- Malware type
- rat, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-22 03:55:48
- Profile updated
- 2026-07-07 13:14:22
Targeted industries: professional-services financial-services technology-and-telecommunications
Context
XenoRAT is an open source remote access trojan written in C#. It can monitor user activity including keystrokes, and provide remote control over the compromised system.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Xenorat (yara-rule)
Reports & references
- Cisco Talos — Moonpeak Malware Infrastructure North Korea (report)
- seqrite.com — Goodbye Hta Hello Msi New Ttps And Clusters Of An Apt Driven By Multi Platform Attacks (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Xenorat (report)
- hunt.io — Xenorat Excel Xll Confuserex As Access Method (report)
- hunt.io — Good Game Gone Bad Xeno Rat Spread Via Gg Domains And Github (report)
- trellix.com — Dprk Linked Github C2 Espionage Campaign (report)
- github.com — Xeno Rat (report)
- axmahr.github.io — Xenorat Detection (report)
- cyfirma.com — Xeno Rat A New Remote Access Trojan With Advance Capabilities (report)