LxBase RAT first observed in attacks on Russian companies
Between July and September 2026, we observed mass phishing campaigns targeting Russian companies across various sectors, including finance, engineering, manufacturing, energy, retail, agriculture, transportation, construction, and IT.
The emails contained the LxBase RAT (remote access trojan), which had not been previously observed in attacks against organizations in the Russian Federation. To deliver LxBase RAT to target systems, threat actors used obfuscated JavaScript loaders packed in RAR archives with a .tar extension. Analysis of information from underground sources revealed that LxBase RAT is distributed under a malware‑as‑a‑service (MaaS) model and offered under the name LX RAT, alongside LX Crypter.
Key findings
- LxBase RAT presents a low barrier to entry for threat actors. A MaaS subscription costs $119 per month and provides access to a fully functional remote access trojan, as well as a crypter to bypass security solutions. Thus, for a relatively low cost, threat actors obtain a ready‑made toolkit for conducting attacks and enhancing their stealth.
- To deliver the LxBase RAT malware, threat actors use phishing emails mimicking business correspondence from employees of Kazakhstani companies. The emails contain malicious archives disguised as documents related to fake orders or requests for quotes. This approach increases the credibility of the messages and the likelihood of recipient response.
- Threat actors employ a multistage LxBase RAT delivery chain, which includes a RAR archive, JS and PowerShell loaders, and a .NET DLL assembly. At the final stage, the LxBase RAT payload is injected into the legitimate MSBuild.exe process, allowing the malware to masquerade its execution as activity from a trusted system component and complicate detection.
Phishing campaigns
Threat actors distributed phishing emails impersonating employees of Kazakhstani companies. In one case, recipients were asked to review an order identified by a number. In another, threat actors simulated a purchase order, asking the recipient to provide the best price quote for items from the attached list. The phishing emails contained a RAR archive with a .tar extension.
The phishing emails had the following subject lines:
- [redacted]_Order_[0‑9]{15,17} (e.g., [redacted]_Order_17954223003082026)
- [redacted]_Order_[0‑9]{15} (e.g., [redacted]_Order_180093804082026)
- Запрос на ценовое предложение // Request for a Quote
Compromise chain
Since the compromise chains in the analyzed attacks are identical, we will examine just one of them.
Inside the RAR archive was an obfuscated JS loader with a name matching the archive, for example: Заказ_17954243003082026_[redacted]_xlsx.js. After the user executed the malicious JS script, the following actions were performed:
- Creation of a JS loader copy:
%APPDATA%\Microsoft\PhotoEngine\PhotoStudio.js. - Creation of a VBS file to launch a JS loader copy:
%APPDATA%\Microsoft\PhotoEngine\PhotoStudio.vbs. Content ofPhotoStudio.vbs:CreateObject("WScript.Shell").Run "wscript.exe " & Chr(34) & "%LOCALAPPDATA%\Microsoft\PhotoEngine\PhotoStudio.js" & Chr(34), 0, FalseIn other attacks, instead of a VBS file, a Batch filenet_109049_e213.cmdwas created. It pipes the contents of the PowerShell scriptrun_13957_e1d4.datvia standard input to thepowershell.exeprocess launched with the-nop -w h -Command‑ parameters. After executing the script, the Batch file deletesrun_13957_e1d4.dat, as well as the files containing the encoded and encrypted payload (log_60134_e1d4andrun_46361_e1d4), deletes the%TEMP%\h97nc9i4directory, and terminates execution and then self‑deletes.Content ofnet_109049_e213.cmd:@type "%TEMP%\h97nc9i4\run_13957_e1d4.dat" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -nop -w h -Command - @del "%TEMP%\h97nc9i4\run_13957_e1d4.dat" 2>nul @del "%TEMP%\h97nc9i4\log_60134_e1d4" 2>nul @del "%TEMP%\h97nc9i4\run_46361_e1d4" 2>nul @rd "%TEMP%\h97nc9i4" 2>nul @(goto) 2>nul & del "%~f0"
- Creation of a Windows Task Scheduler job named
MicrosoftEdgeUpdateTaskCore, which executes the following command every time the current user logs in:C:\Windows\system32\wscript.exe //B //Nologo "%LOCALAPPDATA%\Microsoft\PhotoEngine\PhotoStudio.vbs"
Creation of a randomly named directory (e.g.,
hcy9k4b) in%TEMP%, into which files with random names are written:net_35550_1f98.ps1, a PowerShell script that decodes and decrypts the filesrun_53580_1f79andnet_76020_1f89, and then reflectively loadsMatryoshka.dllinto the memory of thepowershell.exeprocessrun_53580_1f79, an encoded and encryptedMatryoshka.dllpacked with Crypto Obfuscator. This DLL injects theLXBASE.exepayload intoC:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exenet_76020_1f89, an encoded and encryptedLXBASE.exe(LxBase RAT) payloadrun_100412_20c2.vbs, a VBS file designed to launchnet_35550_1f98.ps1
Execution of the
run_100412_20c2.vbsscript to silently launch the PowerShell scriptnet_35550_1f98.ps1Content of
run_100412_20c2.vbs:CreateObject("WScript.Shell").Run "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoP -EP Bypass -NonInteractive -WindowStyle Hidden -File ""%TEMP%\hcy9k4b\net_35550_1f98.ps1""", 0, TrueUsing the
-WindowStyle Hiddenparameter allowed the PowerShell script to execute invisibly.Execution of the PowerShell script
net_35550_1f98.ps1, which acts as a payload loader:- reads the files
run_53580_1f79andnet_76020_1f89 - decodes their contents using a Base52 algorithm with a custom alphabet
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz - performs arithmetic operations to decrypt the file contents: ROR + XOR (with key bytes) + XOR (with a given constant)
- decrypts the file contents using the AES‑CBC + PKCS7 algorithm
- unpacks the decrypted payload:
New-Object System.IO.Compression.DeflateStream($msi, ([System.IO.Compression.CompressionMode]::Decompress))
- reflectively loads the .NET assembly
Matryoshka.dllinto the memory of its ownpowershell.exeprocess and transfers control to it - deletes itself and the files
run_53580_1f79andnet_76020_1f89:Remove-Item '%TEMP%\hcy9k4b\run_53580_1f79','%TEMP%\hcy9k4b\net_76020_1f89','%TEMP%\hcy9k4b\net_35550_1f98.ps1' -Force -EA 0
net_35550_1f98.ps1contains the#XLOADERcomment in its code:
However, this comment is not related to the FormBook/XLoader malware family and most likely represents an internal developer tag or an artifact of the tooling used.
- reads the files
-
Execution of
Matryoshka.dll, which provides a method for injecting malicious code into the address space of an arbitrary process running on the system.The method receives the following parameters:
- path to the executable file of the process into which the LxBase RAT payload will be injected (in the analyzed samples, this path pointed to
MSBuild.exe) - injected payload as a byte array
- delay before launching the injected payload, in milliseconds (in the analyzed samples, this was 45,000 milliseconds, or 45 seconds)
- additional command‑line arguments for the launched process
- boolean parameter
EnableDiagnosticTrace
- path to the executable file of the process into which the LxBase RAT payload will be injected (in the analyzed samples, this path pointed to
- After the final payload is injected into the address space of
MSBuild.exe, LxBase RAT initializes. The malware creates a hidden system directory and writes a file to it with Hidden and System attributes. The file records the timestamp of the malware installation in the formatyyyy-MM-dd HH:mm:ss UTC. In the analyzed samples, the directory was created at%LOCALAPPDATA%\WindowsTelemetry, and the file was namedinstalled.dat. - Before establishing a connection to the C2 server
lxrrxl.ydns[.]eu:4521, system information is gathered using the BuildHandshake method and sent to the C2 server via the Send method. The Send method takes two parameters: a NetworkStream and a data packet as a byte array. Additionally, LxBase RAT creates a unique mutex (e.g.,62269c1cd1394d6fac0a26b7fcc0b0ef). If a mutex with this name already exists, repeated execution of LxBase RAT is prevented.
LxBase RAT
LxBase RAT offers a wide range of capabilities. It allows threat actors to control compromised systems, exfiltrate data from a large number of applications, supports Hidden Virtual Network Computing (HVNC) functionality, and features a built‑in keylogger. Communication with the C2 server relies on a custom protocol operating over TCP. Each data packet begins with a one‑byte command identifier, followed by a four‑byte length field, and then the payload as a byte array.
Depending on the method invoked, the payload may contain various data. For example, when the BuildHandshake method is called, it includes the following system information: ISP, city, country code and name, OS version and architecture, username, computer name, administrative privileges status, malware version and build date, malware installation date and time, timestamp of the last keyboard or mouse activity, and the name of the current process or running executable.
A separate subroutine sends a KeyloggerResponse packet to the C2 server, notifying it of the keylogger activation. The command handler for instructions received from the C2 server reads the command identifier, verifies the specified payload length (which must not exceed 64 MB), and passes control to the corresponding function to execute the received command.
Applications targeted by LxBase RAT for data exfiltration include:
- Web browsers: Chrome, Chrome Beta, Edge, Brave, Avast Secure Browser, Chrome Canary, Chrome Dev, Opera, Opera GX, Vivaldi, Yandex Browser, Cốc Cốc, Torch, Comodo Dragon, SRWare Iron, Epic Privacy Browser, CentBrowser, 360 Safe Browser, QQ Browser, UC Browser, Sogou Browser, Liebao Browser, 2345 Browser, Firefox, and Waterfox.
- Email clients: Thunderbird, Outlook, and Foxmail.
- Multifunctional internet suites: SeaMonkey.
- Cryptocurrency wallet applications: Exodus, Atomic Wallet, Jaxx, Coinomi, Guarda, Bitcoin, Litecoin, Dash, Electrum, Ethereum, Monero, Zcash, Wasabi Wallet, Binance, Electrum‑LTC, Armory, and Bytecoin.
- Cryptocurrency wallet browser extensions: MetaMask, TronLink, Binance Chain, Coin98, Phantom, Trust Wallet, Coinbase Wallet, Ronin, Exodus, Brave, Rabby, Nami, SubWallet, BitKeep, TON, Keplr, Solflare, OKX, Eternl, SafePal, XDeFi, Trezor, HashPack, Martian, Petra, and Crypto.com.
- Messengers: Telegram and Discord.
LxBase RAT can extract saved passwords, cookies, banking card data, autofill information, authentication tokens, browser encryption keys, and other sensitive data. Additionally, the malware supports clipboard interception and screen capture capabilities. It also features a built‑in file manager, allowing threat actors to exfiltrate arbitrary files from the compromised system. Furthermore, the malware supports code injection into the address space of legitimate processes. Specifically, payloads received from the C2 server can be executed in this manner. LxBase RAT has extensive HVNC capabilities enabling threat actors to launch a fully controlled remote environment, including isolated web browser sessions, with the ability to remotely control their interfaces and interact with them.
LxBase RAT commands can be categorized into the following groups:
- Network connection and malware state management: Ping, Disconnect, Reconnect, Uninstall, Update.
- Data collection: DataRecoveryRequest, Keylogger, AutoScreenshotRequest, AutoClipboardRequest, AutoClipboardData.
- Remote control: RemoteDesktop, RemoteDesktopMouse, RemoteDesktopKey, RemoteDesktopMonitor, RemoteDesktopQuality, RemoteDesktopPing.
- Webcam and audio interception: RemoteWebcam, RemoteMicrophone, RemoteSound.
- HVNC: HvncStart, HvncStop, HvncLaunch, HvncShellStart, HvncShellCmd, HvncShellOutput, HvncClipSet, HvncKeyVk.
- Process management: GetProcessesRequest, DoProcessStart, DoProcessKill.
- Registry operations: RegistryGetKeys, RegistryGetValues, RegistryKeysResponse, RegistryValuesResponse.
- Network management: TcpConnectionsRequest, TcpConnectionKill, TcpConnectionResponse, ReverseProxyConnect, ReverseProxyData, ReverseProxyDisconnect.
- Code execution and file operations: RemoteShell, RemoteExecute, DownloadAndExecute, FileManager.
- Startup management: GetStartupItems, DoStartupItemAdd, DoStartupItemRemove.
- Power management: PowerShutdown, PowerRestart, PowerStandby.
- User and system interaction: RequestElevation, GetSystemInfoRequest, ShowMessageBox, VisitWebsite.
Underground market analysis
During the investigation of LxBase RAT attacks, listings for the sale of two related malicious products were discovered on an underground resource:
- LX RAT
- LX Crypter
The latter is designed to pack the final payload and reduce the likelihood of detection by security solutions. It supports anti‑analysis features, including virtualized environment detection.
The LX home page contains information about the LX tools, as well as a link to contact the seller via Telegram. Both tools have been advertised on an underground forum since at least April 2026. Additionally, we identified a YouTube channel belonging to the developer that has been active since at least March 2026. The channel demonstrates how to bypass detection by common antivirus products from both Russian and international vendors.
The LxBase RAT control panel is designed as a classic dashboard featuring a list of active compromised devices. For each device, it displays the IP address, tag, USER@PC, status, connection latency, country, operating system, account type, active window, and time of last activity.
LX Crypter is responsible for packing the final payload and reducing the likelihood of detection. The crypter claims to support FUD (Fully Undetectable) capabilities and can output the final payload in EXE, BAT, JS, VBS, MSI, and ISO formats. It supports both .NET and native code, as well as x86 and x64 architectures.
Obfuscation and protection levels:
- assembly obfuscation, including string encryption and symbol renaming
- string encryption using AES‑256‑CBC with runtime decryption
- Control Flow Obfuscation, transforming the program’s logic to hinder the reconstruction of its original structure and execution sequence
- detection of attempts to modify the executable file
Anti‑analysis and packing mechanisms:
- detection of virtual machines and virtualized environments prior to payload execution
- enforcement of a single malware instance execution via a mutex
- injection into legitimate processes, using hidden task names in Task Manager
- bundling multiple files into a single executable
- spoofing of executable file metadata
- artificial inflation of file size
- deferred execution of the final payload
- ensuring persistence via auto‑start mechanisms
Both tools are sold under a single subscription with a single‑device license for $119 per month, $255 for three months, or $1,020 per year.
Indicators of compromise
Checksums
9c45e0155ba9cfa6f7de048c16003b6ee2d1e965813ac2131022737e5b65186e8b6ee91adc94dfffcc0bc245d6a0db4c367d3a4755d544e849bf67fd253f8ea6b43bb0c7fd0dcc73ece88c856917adc88dd47b030b4cfd61e7ad518ed218104c7b6c39570c0a6976be7b23e035ff3c3c321cccbc50052c027eefc1439c3013fec863ab042e42ec0415b1e09e9cbf92e6c55dfed332b22cf1df0c647c071db85aba28225298ecc362b4d7b829b29d2bc0b3233587832cce53fde2dcfb9f0d0574586f772c71960ccffce550c0fffff9bc7086c143a8b8cd0ce618bfd15f1ffd174d4f76e687fa4248246ca98fc501c6dcad01cd3c1cb53de3c38fa2555900167184d7fef5df408ccd5e3441512af6c6772e0e2d8a76d15a1ccebe1f2d4ef61c42aaf2aeccff1750395cce5128bd1a47a948b8056690666aa3bf63f9d6971167d969fb84a8bf70b92a291c4e7f64b2a566bcd1dbafe2f0215e49c520aa14d1bdbef99ccb0a67e929f83ce55296c9c5cbbc8248516eaae1e299f508f23be63054172bdb865c80afc6f8eac8747cefd827954b072db11f24054d71e7cb2cc5890a07
35f21ee165d26ab28ef286fe67d6d0c27e67277173a514334d19a27996c0527870d5fc3de2c4a4e60c72e6840f436e10167b9844f06e6667732eb58a738e191a6231d4b45837712f547f698fe1de3fb03a71fd793ee2066f5a89487bfa1595d1126390fff28e625ad7e7696802e410810f3f092096dc5c3a385842a661ed7d391fb723fb6e44f75b18aa920dc8d43f3121a8a990b096c681d3733446b54ba8c6de44ed664d71451374801b94b75e836dbaf094b6117fdba8307be47a8d480188f1f29d8921d90f40c0571d7f2cea25e6a98b7a4827f14eeb613c7c2cbcd16c7fbf5abb5d8ed08b97a2712083d4bde0453fcc5d6d79de9664ee028f0741c5cb7e6d1d682be71ae048aa3c54806590c97efb7ab2e824f1a5ac98819f166903cf9376e65afc4d1e093b2d925de571f32b07069db911edf981643228f89c4539c1ee8ea82e2e22c82fc92dec1c5d8b6860b2775ff8d4690841085052863cebbfa8f683bb3c74f78f51469145fd0d935015e00e81cd727b7ae54c002ba54499577980638453730108ca41d1961abe96084a70339fde59ad151a0128024a1b5c7bb1cd
Network indicators
lxrrxl.ydns[.]eu
217.64.151[.]119
MITRE ATT&CK
| Tactic | Technique | Procedure |
|---|---|---|
Initial Access |
Phishing: Spearphishing Attachment |
Threat actors distribute LxBase RAT via phishing emails containing RAR archive attachments with JS loaders. Example archive names: |
| Execution |
Command and Scripting Interpreter: PowerShell |
Use a PowerShell loader to execute a malicious DLL and inject LxBase RAT into the
Use LxBase RAT to execute PowerShell scripts on command from the C2 server:
|
|
Command and Scripting Interpreter: Windows Command Shell |
Use a malicious Batch file to launch the PowerShell loader:
|
|
|
Command and Scripting Interpreter: Visual Basic |
Use a VBS file to launch the PowerShell loader:
|
|
|
Command and Scripting Interpreter: JavaScript |
Use obfuscated JS loaders that create a copy of the loader, generate temporary files with random names, and launch the next stage as a VBS or Batch file:
|
|
|
Native API |
Use LxBase RAT to utilize Windows API functions for injecting code into other processes: VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, ResumeThread |
|
|
User Execution: Malicious File |
Prompt the victim to extract the RAR archive and execute the contained JS file to initiate the system compromise |
|
|
Windows Management Instrumentation |
Use LxBase RAT to execute WMI queries for gathering system information and details about installed antivirus software |
|
| Persistence |
Scheduled Task/Job: Scheduled Task |
Use a JS loader to establish persistence via a scheduled job:
|
| Stealth |
Deobfuscate/Decode Files or Information |
Use LxBase RAT and loaders capable of decrypting their strings, configurations, and payloads |
|
Execution Guardrails: Mutual Exclusion |
Use LxBase RAT to create and check a unique mutex to prevent multiple instances of the malware from running |
|
|
Hide Artifacts: Hidden Files and Directories |
Use LxBase RAT to create a hidden system directory |
|
|
Hide Artifacts: Hidden Window |
Use LxBase RAT to create a hidden remote desktop (HVNC) on the compromised system upon command from the C2 server |
|
|
Indicator Removal: File Deletion |
Use a PowerShell script for self‑deletion and to delete encoded and encrypted files:
Use a Batch file that deletes the PowerShell script, files with encoded and encrypted payloads, and the The Batch file then deletes itself:
|
|
|
Masquerading |
Masquerade JS loaders as documents by using substrings like Example JS loader names:
|
|
|
Obfuscated Files or Information |
Use obfuscation to hinder the analysis of LxBase RAT components. The JS loader code, the .NET assembly used for code injection (protected by Crypto Obfuscator), and LxBase RAT itself are obfuscated |
|
|
Obfuscated Files or Information: Encrypted/Encoded File |
Encrypt the payload using AES‑CBC, apply ROR and XOR operations to the resulting data, and then encode it using Base52 |
|
|
Obfuscated Files or Information: Compression |
Unpack the decrypted payload using a PowerShell loader with the Deflate algorithm:
|
|
|
Process Injection |
Use a malicious DLL to inject LxBase RAT into the |
|
|
Reflective Code Loading |
Use PowerShell loaders and LxBase RAT to reflectively load payloads |
|
|
Virtualization/Sandbox Evasion |
Сan potentially use LX Crypter to check the execution environment for signs of virtualization |
|
| Credential Access |
Credentials from Password Stores |
Use LxBase RAT to search for and extract saved credentials from Thunderbird, Microsoft Outlook, and Foxmail email clients |
|
Credentials from Password Stores: Credentials from Web Browsers |
Use LxBase RAT to steal saved credentials from Chromium‑ and Gecko‑based browsers, including passwords, bank card data, autofill information, browser encryption keys, Local State secrets, and data protected by DPAPI and App‑Bound Encryption (ABE). For Firefox browsers, extraction of credentials protected by the NSS library ( |
|
|
Steal Web Session Cookie |
Use LxBase RAT to steal browser cookies from Chromium‑ and Gecko‑based browsers, including Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi, Yandex Browser, Firefox, and other supported browsers |
|
| Discovery |
File and Directory Discovery |
Use LxBase RAT to collect information about files and directories |
|
Process Discovery |
Use LxBase RAT to obtain information about running processes |
|
|
Software Discovery: Security Software Discovery |
Use LxBase RAT to obtain information about installed antivirus software. The malware uses two methods:
|
|
|
System Information Discovery |
Use LxBase RAT to collect system information, including computer name, OS version, build type, and architecture, as well as CPU, RAM, and GPU details |
|
|
System Location Discovery |
Use LxBase RAT to obtain the ISP, city, country, and country code via the |
|
|
System Location Discovery: System Language Discovery |
Use LxBase RAT to obtain information about the language used on the compromised system |
|
|
System Network Connections Discovery |
Use LxBase RAT to obtain the internal IP address, as well as the victim’s external IP address using the |
|
|
System Owner/User Discovery |
Use LxBase RAT to obtain the current username and determine if the user has administrator privileges |
|
| Collection |
Audio Capture |
Use LxBase RAT to intercept microphone data and system sounds |
|
Clipboard Data |
Use LxBase RAT to obtain the contents of the clipboard |
|
|
Data from Local System |
Use LxBase RAT to retrieve files and data |
|
|
Input Capture: Keylogging |
Use LxBase RAT to record keystrokes |
|
|
Screen Capture |
Use LxBase RAT to take screenshots |
|
|
Video Capture |
Use LxBase RAT to capture images from the compromised system’s webcam |
|
| Command and Control |
Ingress Tool Transfer |
Use LxBase RAT to deliver additional malicious payloads to the compromised system, as well as to update the LxBase RAT malware |
|
Non‑Application Layer Protocol |
Use LxBase RAT for network communication via a custom protocol operating over TCP |
|
|
Non‑Standard Port |
Use network port 4521 in LxBase RAT for communication with the C2 server |
|
| Exfiltration |
Automated Exfiltration |
Use LxBase RAT to automatically exfiltrate various files and data to the C2 server |
|
Exfiltration Over C2 Channel |
Use LxBase RAT to transit stolen data to the C2 server |
BI.ZONE Mail Security helps block emails with malicious attachments at the network perimeter. The solution employs more than 100 filtering mechanisms, including machine vision, YARA rules, and methods of statistical, signature, linguistic, content, and heuristic analysis. It leverages several AI models alongside built‑in protection against server auto‑reply loops and bounce messages. This approach allows organizations to filter out unwanted messages without slowing down the delivery of secure correspondence.
Staying proactive requires an understanding of the methods and tools used by adversaries. The BI.ZONE Threat Intelligence portal provides up‑to‑date details on attackers, their tactics, techniques, tools, along with threat detection recommendations. This enables organizations to integrate cyber threat intelligence into their security operations and prevent future incidents.