XenoRAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
January 23, 2026
Last Seen
May 30, 2026

XenoRAT is a malware family tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed January 23, 2026; most recent activity May 30, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • SideCopy Deploys Persistent XenoRAT Against Afghanistan Finance Ministry — Gbhackers · May 30, 2026
  • SideCopy Deploys Persistent XenoRAT Against Afghanistan Finance Ministry — Gbhackers · May 30, 2026
  • Kimsuky targets organizations with PebbleDash — Securelist · May 14, 2026
  • North Korea Uses GitHub as C2 in New LNK Phishing Campaign — Gbhackers · April 3, 2026
  • Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems — Cybersecuritynews · January 23, 2026

CVSS v3.1 Breakdown