This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
XtremeRAT is a publically available remote access trojan (RAT).
Affected platforms
The following platforms are known to be affected:
Threat details
Originally created in 2010, it has received numerous updates and has been used as the basis for several other RAT tools.
Primarily delivered via medium-scale spam campaigns, XtremeRAT will attempt to install a backdoor in order to communicate with its command and control infrastructure.
XtremeRAT has the following capabilities:
- Target interaction via remote shell.
- Transfer and execute files.
- Manipulate processes and services.
- Alter registry entries.
- Capture desktop images.
- Record from connected devices, such as webcams or mice, with the recorded data written to an RC4 encrypted log file.
Alongside this, it is also able to infect USB devices for increased propagation.
Threat updates
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
Last edited: 17 February 2020 12:58 pm