LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0117: XTunnel

XTunnel a VPN-like network proxy tool that can relay traffic between a C2 server and a victim. It was first seen in May 2013 and reportedly used by APT28 during the compromise of the Democratic National Committee. [1] [2] [3]

EnterpriseS0117MalwareObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

XTunnel matters because it is described as a VPN-like proxy that can relay traffic between a command-and-control server and a victim Windows environment. For leaders, the practical issue is not the malware name alone; it is whether the organization can see and control unauthorized proxying, fallback communications, encrypted C2 traffic, and command execution that may let an intruder maintain access and move traffic through trusted networks.

Executive priority

Prioritize XTunnel as a resilience and incident-response readiness concern where Windows systems, sensitive networks, or high-value identities are in scope. The ATT&CK relationships point to command-and-control proxying, fallback channels, asymmetric cryptography, Windows command shell execution, discovery, credential search in files, and obfuscation. Executives should ask whether network monitoring, endpoint telemetry, egress controls, credential storage hygiene, and incident containment playbooks can prove coverage for those behaviors, not just whether a signature exists for this malware family.

Technical view

ATT&CK provides no official detection text for XTunnel, so defenders should validate behavior-based coverage around the related techniques: Proxy, Fallback Channels, Asymmetric Cryptography, Windows Command Shell, Network Service Discovery, Credentials in Files, Obfuscated Files or Information, and Junk Code Insertion. SOC teams should test whether Windows endpoint telemetry and network controls can identify unusual proxy-like processes, unexpected outbound destinations, fallback C2 patterns, encrypted traffic inconsistent with normal application behavior, suspicious cmd.exe use, scanning or service enumeration, and access to files likely to contain credentials. Relationship context also notes reported use by APT28, but local detection should be based on observable behaviors and environment baselines rather than attribution assumptions.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry, especially cmd.exe activity
  • Network connection metadata from endpoints, proxies, firewalls, DNS, and secure web gateways
  • Egress traffic logs showing unusual relay/proxy behavior or alternate communication paths
  • TLS or encrypted-session metadata where available, without assuming content visibility
  • File access telemetry for configuration files, shared locations, backups, or other files that may contain credentials

Detection direction

  • Because MITRE does not provide an official detection section, validate detections against the related ATT&CK techniques rather than relying on a single XTunnel indicator.
  • Tune for abnormal outbound proxying from Windows hosts, especially systems that do not normally relay traffic or initiate broad external communications.
  • Correlate command shell execution with network activity, service discovery, and credential-file access to reduce false positives from legitimate administration.
  • Review blind spots in encrypted C2 visibility: asymmetric cryptography may hide content, so metadata, process ownership, destination reputation, timing, and host context become important.
  • Check whether fallback-channel behavior would be noticed if a primary destination were blocked, including repeated attempts to alternate destinations or protocols.

Mitigation priorities

  • Enforce least-privilege egress controls so Windows hosts only communicate externally where business-required.
  • Strengthen endpoint monitoring and response coverage for command execution, suspicious network processes, file access, and service discovery.
  • Reduce credential exposure by finding and removing insecure credentials stored in files, shared locations, backups, or configuration data.
  • Segment sensitive networks so a proxy tool on one host cannot freely relay traffic across critical environments.
  • Maintain incident response playbooks for suspected command-and-control proxying, including host isolation, network block validation, credential review, and scope assessment.
Additional notes and limits

XTunnel is a malware/software object in enterprise ATT&CK with Windows listed as the platform. The supplied description says it is a VPN-like network proxy tool first seen in May 2013 and reportedly used by APT28 during the Democratic National Committee compromise. The strongest defensive value comes from the relationship-mapped behaviors: proxying, fallback channels, encrypted C2, command shell execution, discovery, credential-file access, and obfuscation.

The object has no official ATT&CK detection guidance and no object-level tactics are specified. Several related techniques list broader platforms, but the XTunnel object itself is supplied with Windows as its platform; this take does not extend XTunnel platform scope beyond that. Local telemetry, baselines, and confirmed indicators are required to assess actual exposure or detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

XTunnel

XTunnel a VPN-like network proxy tool that can relay traffic between a C2 server and a victim. It was first seen in May 2013 and reportedly used by APT28 during the compromise of the Democratic National Committee. [1] [2] [3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

8 rows
DomainIDNameRelationship / procedure
EnterpriseT1552.001Credentials In FilesSub-technique

XTunnel is capable of accessing locally stored passwords on victims.[2]

EnterpriseT1027.016Junk Code InsertionSub-technique

A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products.[3]

EnterpriseT1059.003Windows Command ShellSub-technique

XTunnel has been used to execute remote commands.[1]

EnterpriseT1046Network Service Discovery

XTunnel is capable of probing the network for open ports.[2]

EnterpriseT1573.002Asymmetric CryptographySub-technique

XTunnel uses SSL/TLS and RC4 to encrypt traffic.[2][3]

EnterpriseT1090Proxy

XTunnel relays traffic between a C2 server and a victim.[1]

EnterpriseT1027Obfuscated Files or Information

A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products.[3]

EnterpriseT1008Fallback Channels

The C2 server used by XTunnel provides a port number to the victim to use as a fallback in case the connection closes on the currently used port.[3]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.1
Created
Modified
Raw hash
6afaad167b53ab1b...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.1Current bundle6afaad167b53…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Crowdstrike DNC June 2016

    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

    Open source URL
  2. [2]
    Invincea XTunnel

    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

    Open source URL
  3. [3]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  4. [4]
    ESET Sednit Part 3

    ESET. (2016, October). En Route with Sednit - Part 3: A Mysterious Downloader. Retrieved November 21, 2016.

  5. [5]
    Symantec APT28 Oct 2018

    Symantec Security Response. (2018, October 04). APT28: New Espionage Operations Target Military and Government Organizations. Retrieved November 14, 2018.

    Open source URL
  6. [6]
    US District Court Indictment GRU Oct 2018

    Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.

    Open source URL
  7. [7]
    Secureworks IRON TWILIGHT Active Measures March 2017

    Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.

    Open source URL
  8. [8]
    Crowdstrike DNC June 2016

    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

    Open source URL
  9. [9]
    Crowdstrike DNC June 2016

    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

    Open source URL
  10. [10]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  11. [11]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  12. [12]
    Invincea XTunnel

    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

    Open source URL
  13. [13]
    Invincea XTunnel

    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

    Open source URL
  14. [14]
    Symantec APT28 Oct 2018

    Symantec Security Response. (2018, October 04). APT28: New Espionage Operations Target Military and Government Organizations. Retrieved November 14, 2018.

    Open source URL
  15. [15]
    Symantec APT28 Oct 2018

    Symantec Security Response. (2018, October 04). APT28: New Espionage Operations Target Military and Government Organizations. Retrieved November 14, 2018.

    Open source URL
  16. [16]
    Trojan.Shunnael

    (Citation: Symantec APT28 Oct 2018)

  17. [17]
    Trojan.Shunnael

    (Citation: Symantec APT28 Oct 2018)

  18. [18]
    Trojan.Shunnael

    (Citation: Symantec APT28 Oct 2018)

  19. [19]
    X-Tunnel

    (Citation: Crowdstrike DNC June 2016)(Citation: Symantec APT28 Oct 2018)

  20. [20]
    X-Tunnel

    (Citation: Crowdstrike DNC June 2016)(Citation: Symantec APT28 Oct 2018)

  21. [21]
    X-Tunnel

    (Citation: Crowdstrike DNC June 2016)(Citation: Symantec APT28 Oct 2018)

  22. [22]
    XAPS

    (Citation: ESET Sednit Part 2)

  23. [23]
    XAPS

    (Citation: ESET Sednit Part 2)

  24. [24]
    XAPS

    (Citation: ESET Sednit Part 2)

  25. [25]
    XTunnel

    (Citation: ESET Sednit Part 2)

  26. [26]
    XTunnel

    (Citation: ESET Sednit Part 2)

  27. [27]
    XTunnel

    (Citation: ESET Sednit Part 2)

  28. [28]
    mitre-attackS0117
    Open source URL
  29. [29]
    mitre-attackS0117
    Open source URL
  30. [30]
    mitre-attackS0117
    Open source URL
  31. [31]
    Invincea XTunnel

    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

    Open source URL
  32. [32]
    Invincea XTunnel

    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

    Open source URL
  33. [33]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  34. [34]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  35. [35]
    Crowdstrike DNC June 2016

    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

    Open source URL
  36. [36]
    Crowdstrike DNC June 2016

    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

    Open source URL
  37. [37]
    ESET Sednit Part 3

    ESET. (2016, October). En Route with Sednit - Part 3: A Mysterious Downloader. Retrieved November 21, 2016.

  38. [38]
    Secureworks IRON TWILIGHT Active Measures March 2017

    Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.

    Open source URL
  39. [39]
    Symantec APT28 Oct 2018

    Symantec Security Response. (2018, October 04). APT28: New Espionage Operations Target Military and Government Organizations. Retrieved November 14, 2018.

    Open source URL
  40. [40]
    Symantec APT28 Oct 2018

    Symantec Security Response. (2018, October 04). APT28: New Espionage Operations Target Military and Government Organizations. Retrieved November 14, 2018.

    Open source URL
  41. [41]
    US District Court Indictment GRU Oct 2018

    Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.

    Open source URL
  42. [42]
    Invincea XTunnel

    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

    Open source URL
  43. [43]
    Invincea XTunnel

    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

    Open source URL
  44. [44]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  45. [45]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  46. [46]
    Invincea XTunnel

    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

    Open source URL
  47. [47]
    Invincea XTunnel

    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

    Open source URL
  48. [48]
    Crowdstrike DNC June 2016

    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

    Open source URL
  49. [49]
    Crowdstrike DNC June 2016

    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

    Open source URL
  50. [50]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  51. [51]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.