logo

XtremeRAT: Nuisance or Threat?

ID: ceb24605-2a2d-4891-9c21-f6c5ba792edc

STIX ID: report--ceb24605-2a2d-4891-9c21-f6c5ba792edc

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2014-08-28

Last Modified Date: 2014-08-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This FireEye analysis examines XtremeRAT — a Delphi-based remote access trojan used in both large-scale spam/banking-malware distribution and some targeted espionage campaigns (e.g., Operation Molerats). The report documents XtremeRAT capabilities (keylogging, file transfer, process injection, webcam/microphone capture), builder-configured artifacts (IDs, groups, mutexes, CnC domains, default passwords), methods for extracting encrypted configuration from disk and memory, sample clustering by config and CnC, sinkhole telemetry (urenio2.no-ip.biz with ~12k unique IPs), and provides scripts and IOCs to support tracking and attribution.