XServer

Aliases: Filesnfer

First seen
2016-04-15 00:00:00
Malware type
rat, credential-stealer, loader
Family
Malware family
Profile updated
2026-07-07 15:27:06

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

XServer, also known as Filesnfer, is a remote access trojan (RAT) that enables attackers to gain unauthorized access to affected systems. It often targets technology and government sectors, focusing on data theft and establishing control through command-and-control servers.

Detection coverage

  • 3 YARA rules

Detection rules

  • SIGNATURE_BASE_APT_MAL_CN_Wocao_Xserver_Csharp (yara-rule)
  • SIGNATURE_BASE_APT_MAL_CN_Wocao_Xserver_Powershell_B64Encoded (yara-rule)
  • SIGNATURE_BASE_APT_MAL_CN_Wocao_Xserver_Powershell_Dropper (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Xserver (report)
  • resources.fox-it.com — 201912 Report Operation Wocao (report)
  • norfolkinfosec.com — Filesnfer Tool C Python (report)

External references