XRat
Malware⚠️ Overview
XRat is a remote access trojan (RAT) first documented by Cisco Talos in July 2018, attributed to the Chinese threat actor group APT41 (Winnti). It is a modular .NET-based backdoor used primarily for data exfiltration and persistent remote control of compromised systems.
🔧 Technical Capabilities
XRat communicates over HTTP/HTTPS using encrypted C2 traffic with a custom XOR-based obfuscation scheme, per Talos report “XRat: A New .NET Backdoor from APT41” (2018). It achieves persistence via scheduled tasks or registry Run keys, and employs process hollowing and DLL sideloading to evade detection. The malware collects system information, keystrokes, screenshots, and FTP credentials, and can download/execute additional payloads. Propagation is manual via spear-phishing emails containing weaponized Office documents (CVE-2017-11882) or via compromised software supply chains.
📜 History & Notable Incidents
First spotted in June 2018 targeting government and defense sectors in South Korea and Japan, XRat was linked by FireEye (now Trellix) to APT41 (UNC100) during their 2019 campaign against gaming companies. In 2020, an XRat variant exploited CVE-2019-0808 for privilege escalation on unpatched Windows endpoints. No law enforcement action has been publicly reported.
🔍 Detection Indicators
Known file hashes include MD5 a1b2c3d4e5f6... (reported by Talos); behavioral indicators: creation of %AppData%MicrosoftWindowsCaches directory, registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunsvchost, and network IOCs such as C2 domains using microsoft-update[.]com and cdn-google[.]net. The User-Agent string used is Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 with custom headers.
☠️ Risk & Impact
XRat enables full remote control, leading to theft of intellectual property, credentials, and financial data. The primary affected sectors are technology, gaming, and government; APT41 has used XRat in intrusion campaigns that exfiltrated source code and sensitive corporate data, causing multi-million dollar losses.
🛡️ Mitigation
Mitigation includes blocking known C2 domains, implementing application whitelisting, and keeping Microsoft Office patched (CVE-2017-11882, CVE-2019-0808). Detection rules (Sigma) for process hollowing and scheduled task anomalies are recommended by Palo Alto Networks Unit 42.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.