Xtreme RAT

Aliases: ExtRat

First seen
2012-01-01 00:00:00
Malware type
rat, keylogger, screen-capture, backdoor
Family
Malware family
Last IoC activity
2026-07-22 00:38:41
Profile updated
2026-07-07 12:49:39

Targeted industries: government-and-public-sector

Targeted regions: country_code:il country_code:sy

Context

According to Trend MIcro, Extreme RAT (XTRAT, Xtreme Rat) is a Remote Access Trojan that can steal information. This RAT has been used in attacks targeting Israeli and Syrian governments last 2012. This malware family of backdoors has the capability to receive commands such as File Management (Download, Upload, and Execute Files), Registry Management (Add, Delete, Query, and Modify Registry), Perform Shell Command, Computer Control (Shutdown, Log on/off), and Screen capture from a remote attacker. In addition, it can also log keystrokes of the infected systems.

Reports & references

  • secureworks.com — Aluminum Saratoga (report)
  • citizenlab.ca — Packrat Report (report)
  • embee-research.ghost.io — Practical Queries For Malware Infrastructure Part 3 (report)
  • embeeresearch.io — Practical Queries For Malware Infrastructure Part 3 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Extreme Rat (report)
  • www2.slideshare.net — 1 (report)
  • Broadcom/Symantec — Colombians Major Target Email Campaigns Delivering Xtreme Rat (report)
  • community.rsa.com — Malspam Delivers Xtreme Rat 8 1 2017 (report)
  • blogs.360.cn — Apt C 44 (report)
  • mp.weixin.qq.com — Gwoirnplvqx761Lw8X S5G (report)
  • malware.lu — Xtreme Rat Analysis (report)
  • Mandiant — Xtremerat Nuisance Or Threat (report)

External references