Skip to main content

Boteraser | Website and Server Security Solutions

XenoRAT

Malware

⚠️ Overview

XenoRAT is a open-source remote access trojan (RAT) first identified in public repositories on GitHub in April 2023, developed by an unknown individual under the pseudonym "Amd64" and later forked by other actors. It is categorized as a commodity RAT used for espionage, credential harvesting, and remote control, often deployed via phishing campaigns or bundled with cracked software.

🔧 Technical Capabilities

XenoRAT is written in C# and utilizes a client-server architecture with encrypted C2 communications over TCP, supporting custom encryption keys. Propagation methods include dropping itself into startup folders, registry run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run), and scheduled tasks. It features keylogging, screen capture, webcam and microphone access, file exfiltration, and remote shell execution. Evasion techniques include API unhooking, anti-debugging checks, and polymorphic code generation via a built-in crypter. Persistence is achieved through service installation or WMI event subscriptions. The malware also enumerates antivirus software and can disable Windows Defender via registry manipulation (MITRE ATT&CK T1562.001).

📜 History & Notable Incidents

XenoRAT first appeared in April 2023 on GitHub and was rapidly adopted by multiple threat actors, as documented by the Palo Alto Networks Unit 42 report in September 2023. A notable campaign in early 2024 targeted Indian government employees using spear-phishing emails with malicious Excel add-ins (CVE-2023-38831 exploited in WinRAR archives). No major law enforcement actions have been publicly recorded as of 2025. The malware is also linked to attacks against educational institutions in Southeast Asia according to a 2024 Trend Micro analysis.

🔍 Detection Indicators

Known file hashes include SHA256: d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5 (example variant). Behavioral indicators include outbound TCP connections to ports 443 or 8080 on C2 servers using User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with a custom XenoRAT header. Registry persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run\XenoRAT and mutex names like XenoRAT_Mutex are common. Network IOCs include domains with random substrings and IP addresses in hosting ranges from Russia and the Netherlands.

☠️ Risk & Impact

XenoRAT poses a high risk due to its complete remote control capabilities, enabling data exfiltration, credential theft, and potential ransomware deployment. Financial losses have been reported in the manufacturing and healthcare sectors, with Mandiant attributing a 2023 breach in a U.S. hospital to XenoRAT leading to a $500,000 ransom demand. Affected sectors include government, education, and critical infrastructure.

🛡️ Mitigation

Defensive measures include blocking outbound connections to known malicious IPs via SIEM rules, deploying EDR solutions with behavioral detection for process injection and registry modifications, and enforcing strict email attachment policies. The Microsoft Defender signature RAT:MSIL/XenoRAT!MTB can detect it, and organizations should apply CVE-2023-38831 patches immediately.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.