FILEMembers
FILE

XRed RAT Hits Peru Gov With Frozen 2019 Builder, AnyDesk Lures

Three trojanized executables spoofing Synaptics drivers and AnyDesk installers are targeting Peruvian government entities with an XRed RAT payload whose compiled import table has not changed since June 2019. One variant defeated sandbox classification entirely despite detection by 67 of 79 antivirus engines, while the entire C2 infrastructure runs on zero-cost FreeDNS dynamic-DNS services.

Jun 11, 2026, 06:43 (UTC+9)Last seenJun 11, 2026Severity72ByCTX TeamActorCactusCactus Ransomware GroupIOC15MITRE20RegionsPE

Three Windows executables masquerading as a Synaptics touchpad driver and AnyDesk remote-desktop installer are circulating against Peruvian government targets, carrying an XRed RAT payload whose compiled import table has not changed since at least June 2019. The same imphash — 332f7ce65ead0adfb3d35147033aabe9 — locks together samples whose first VirusTotal submissions span four years, from June 2019 through October 2023, and the campaign was still active as recently as May 2026.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence