Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Xeno RAT

81
Global rank
60 infographic chevron month
Month rank
92 infographic chevron week
Week rank
0
IOCs

Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.

RAT
Type
Unknown
Origin
1 October, 2023
First seen
3 February, 2026
Last seen

How to analyze Xeno RAT with ANY.RUN

RAT
Type
Unknown
Origin
1 October, 2023
First seen
3 February, 2026
Last seen

IOCs

IP addresses
147.185.221.24
86.68.222.14
1.229.183.193
193.161.193.99
192.109.200.95
178.17.62.52
159.100.29.122
190.134.167.15
80.71.157.55
190.134.161.62
109.107.168.55
45.95.11.52
190.133.59.8
91.92.248.167
190.134.184.103
158.247.202.109
45.89.247.109
190.133.22.252
45.87.153.79
139.99.36.158
Domains
vlxx.cn.com
reklammenshop.ru
xenosploit.com
bolovirrest.ru
zenofs.zapto.org
wealthxeno.ddnsfree.com
wealthyman.ddnsfree.com
nanoshd.pro
jctestwindows.airdns.org
nanoshield.pro
roollingstonen.sytes.net
fusionmelonate.duckdns.org
busyestinglsv.site
swiftwealth.ddns.net
amazingers.ru
zsebastian.ru
cryptobro.duckdns.org
dentiste.ddns.net
maroni823.sytes.net
super-italic.gl.at.ply.gg
Last Seen at
Last Seen at

Recent blog posts

post image
How Threat Intelligence Helps Protect Financi...
watchers 390
comments 0
post image
Release Notes: Workflow Improvements, MISP In...
watchers 2148
comments 0
post image
Enterprise Phishing: How Attackers Abuse Trus...
watchers 4203
comments 0

What is Xeno RAT malware?

Xeno RAT is an open-source remote access trojan (RAT) distributed openly through GitHub. The creator behind this malicious software states that it was created for educational purposes only. This, however, does not prevent threat actors from leveraging it in their attacks to steal sensitive data and spy on their victims.

Since Xeno RAT is available free-of-charge, there are many amateur and experienced attackers that employ it. Since 2023, the malware has been involved in several campaigns primarily targeting individual users through drive-by downloads.

Xeno RAT is written in C# and is intended to operate on Windows systems. Since the malware is being continuously updated, it poses a serious threat to organizations and users around the world.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Xeno RAT malware technical details

Xeno RAT’s range of capabilities is similar to that of other RATs, such as Asyncrat and njRAT. Some of the malicious activities that can be performed using Xeno RAT include:

  • Xeno RAT allows attackers to remotely control a victim's computer, including accessing and modifying files, installing and uninstalling software, and executing commands.
  • The malware can record every keystroke made on the infected computer, including in the offline mode.
  • One of the standout features of Xeno RAT is the ability to access the webcam and microphone of the infected computer, allowing them to spy on the victim and their surroundings.
  • The malware can be used to steal files from the device, as well as passwords stored in web browsers, email clients, and other software.
  • Attackers using Xeno RAT can also reboot the infected computer, turn off its display, and edit the registry.

Out of all features available to the attackers using the Xeno RAT malware, Hidden Virtual Network Computing offers the most extensive functionality for conducting malicious activities. This utility lets criminals not only take full control of the victim’s computer but also do it stealthily and completely without their notice.

The Socks5 reverse proxy feature of Xeno RAT allows attackers to route their network traffic through a compromised computer, effectively hiding it.

Xeno RAT usually achieves persistence on the compromised system using Scheduled Tasks. It has also been observed to leverage process injection to evade detection.

Xeno RAT execution process

To see how Xeno RAT operates, let’s upload its sample to the ANY.RUN sandbox.

The execution chain of Xeno RAT may be relatively simple, involving only one or two processes, but it can also become complex with the utilization of multiple processes, including built-in OS tools.

XenoRAT scripts in ANY.RUN Xeno RAT script analysis in ANY.RUN

The main malicious activities are carried out by the injected RegAsm process.

In our example, the execution involves multiple processes such as WScript.exe, regsvr32.exe, and RegAsm.exe. The malware creates files in the Startup directory to achieve persistence and loads the dynwrapx.dll (DynamicWrapperX) file. These activities can be monitored using Script Tracer.

For persistence and stealth, XenoRAT can bypass User Account Control (UAC) and maintain its presence even after system reboots using startup functions. It spreads primarily through phishing, exploiting software vulnerabilities, and other typical methods such as downloading from compromised websites or deceptive advertisements.

XenoRAT metadata in ANY.RUN Xeno RAT metadata in ANY.RUN

Sometimes, Xeno RAT builds may inadvertently reveal themselves by naming directories after the malware, such as "xeno rat client" or "XenoManager," or by embedding its name in PE metadata, for instance, as the company name or product name.

Xeno RAT malware distribution methods

As for the most common delivery methods, drive-by downloads constitute the main vector of Xeno RAT attacks. Individual users are the primary target of these. As a result, to trick their victims into downloading and running the malicious software, threat actors may disguise it as video games or software updates.

Conclusion

Xeno RAT’s wide range of features and capabilities, including HVNC, make it a versatile tool for conducting cyber attacks. The open-source nature of this threat highlights the importance of having proper security measures in place to prevent potential attacks.

Using a sandbox like ANY.RUN to analyze suspicious files and URLs should one of such measures. The cloud-based service allows you to detonate any malicious file in a safe and secure environment, while also having the ability to interact with the system just like on your own computer. Use ANY.RUN to study the behavior of malware, understand its TTPs, and collect indicators of compromise.

Create your ANY.RUN account – it’s free!

HAVE A LOOK AT

Trojan screenshot
Trojan
trojan trojan horse
Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.
Read More
Play Ransomware screenshot
Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
WarmCookie screenshot
WarmCookie
badspace
WarmCookie is a backdoor malware that cyber attackers use to gain initial access to targeted systems. It is often distributed through phishing emails, frequently using job recruitment lures to entice victims into downloading and executing the malware.
Read More
Cobalt Strike screenshot
Cobalt Strike
cobaltstrike
Cobalt Strike is a legitimate penetration software toolkit developed by Forta. But its cracked versions are widely adopted by bad actors, who use it as a C2 system of choice for targeted attacks.
Read More