XtremeRAT: Nuisance or Threat?
ID: ceb24605-2a2d-4891-9c21-f6c5ba792edc
STIX ID: report--ceb24605-2a2d-4891-9c21-f6c5ba792edc
Threat Score
72/100
Uploaded: 2026-08-19
Published Date: 2014-08-28
Last Modified Date: 2014-08-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This FireEye analysis examines XtremeRAT — a Delphi-based remote access trojan used in both large-scale spam/banking-malware distribution and some targeted espionage campaigns (e.g., Operation Molerats). The report documents XtremeRAT capabilities (keylogging, file transfer, process injection, webcam/microphone capture), builder-configured artifacts (IDs, groups, mutexes, CnC domains, default passwords), methods for extracting encrypted configuration from disk and memory, sample clustering by config and CnC, sinkhole telemetry (urenio2.no-ip.biz with ~12k unique IPs), and provides scripts and IOCs to support tracking and attribution.
