
XRed RAT Hits Peru Gov With Frozen 2019 Builder, AnyDesk Lures
Three trojanized executables spoofing Synaptics drivers and AnyDesk installers are targeting Peruvian government entities with an XRed RAT payload whose compiled import table has not changed since June 2019. One variant defeated sandbox classification entirely despite detection by 67 of 79 antivirus engines, while the entire C2 infrastructure runs on zero-cost FreeDNS dynamic-DNS services.
Three Windows executables masquerading as a Synaptics touchpad driver and AnyDesk remote-desktop installer are circulating against Peruvian government targets, carrying an XRed RAT payload whose compiled import table has not changed since at least June 2019. The same imphash — 332f7ce65ead0adfb3d35147033aabe9 — locks together samples whose first VirusTotal submissions span four years, from June 2019 through October 2023, and the campaign was still active as recently as May 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read