Netskope Threat Labs

Xtreme RAT

ATP Sandbox Adv. Heuristics

Xtreme RAT (a.k.a. XTRAT) is a remote access trojan that can steal information, and its operators used it in attacks against the Israeli and Syrian governments in 2012. Its backdoor components receive operator commands for file management, registry manipulation, shell commands, system control, and screen capture, and they also log keystrokes on infected systems.

First seen
April 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Backdoor.XtremeRAT
Email-MIME.Backdoor.XtremeRAT
Win32.Backdoor.XtremeRAT