XenoRAT is a open-source remote access trojan (RAT) first identified in public repositories on GitHub in April 2023, developed by an unknown individual under the pseudonym "Amd64" and later forked by other actors. It is categorized as a commodity RAT used for espionage, credential harvesting, and remote control, often deployed via phishing campaigns or bundled with cracked software.
XenoRAT is written in C# and utilizes a client-server architecture with encrypted C2 communications over TCP, supporting custom encryption keys. Propagation methods include dropping itself into startup folders, registry run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run), and scheduled tasks. It features keylogging, screen capture, webcam and microphone access, file exfiltration, and remote shell execution. Evasion techniques include API unhooking, anti-debugging checks, and polymorphic code generation via a built-in crypter. Persistence is achieved through service installation or WMI event subscriptions. The malware also enumerates antivirus software and can disable Windows Defender via registry manipulation (MITRE ATT&CK T1562.001).
XenoRAT first appeared in April 2023 on GitHub and was rapidly adopted by multiple threat actors, as documented by the Palo Alto Networks Unit 42 report in September 2023. A notable campaign in early 2024 targeted Indian government employees using spear-phishing emails with malicious Excel add-ins (CVE-2023-38831 exploited in WinRAR archives). No major law enforcement actions have been publicly recorded as of 2025. The malware is also linked to attacks against educational institutions in Southeast Asia according to a 2024 Trend Micro analysis.
Known file hashes include SHA256: d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5 (example variant). Behavioral indicators include outbound TCP connections to ports 443 or 8080 on C2 servers using User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with a custom XenoRAT header. Registry persistence under HKCU\Software\Microsoft\Windows\CurrentVersion\Run\XenoRAT and mutex names like XenoRAT_Mutex are common. Network IOCs include domains with random substrings and IP addresses in hosting ranges from Russia and the Netherlands.
XenoRAT poses a high risk due to its complete remote control capabilities, enabling data exfiltration, credential theft, and potential ransomware deployment. Financial losses have been reported in the manufacturing and healthcare sectors, with Mandiant attributing a 2023 breach in a U.S. hospital to XenoRAT leading to a $500,000 ransom demand. Affected sectors include government, education, and critical infrastructure.
Defensive measures include blocking outbound connections to known malicious IPs via SIEM rules, deploying EDR solutions with behavioral detection for process injection and registry modifications, and enforcing strict email attachment policies. The Microsoft Defender signature RAT:MSIL/XenoRAT!MTB can detect it, and organizations should apply CVE-2023-38831 patches immediately.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.