logo

XenoRAT Adopts Excel XLL Files and ConfuserEx as Access Method

ID: 0ecb2fe3-edbe-5097-9729-5e0fcb250c1f

STIX ID: report--0ecb2fe3-edbe-5097-9729-5e0fcb250c1f

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report analyzes a XenoRAT remote-access tool delivered as an Excel XLL (Payment_Details.xll) using Excel‑DNA and protected with ConfuserEx; it details the dropper chain (obfuscated batch, passworded SFX RAR, extracted executables), visible decoy PDF, extracted XenoRAT payload (Original.exe) with a hardcoded C2 (87.120.116.115:1391), and provides file and network observables for detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.