Orcus
Orcus is a commercially sold, feature-rich Remote Access Trojan (RAT) written in C# (with a WPF-based Windows controller UI) and marketed since April 2016 for about $40.
Profile source: Mallory opens in a new tabOrcus
Family profile
Orcus is a commercially sold, feature-rich Remote Access Trojan (RAT) written in C# (with a WPF-based Windows controller UI) and marketed since April 2016 for about $40. It uses a three-component architecture—controller (admin panel), server, and victim trojan—where infected hosts connect back to an Orcus server rather than directly to the operator’s controller, enabling shared access among multiple criminals and scalable deployments across multiple servers. Orcus is modular and supports custom plugins (with documented developer packages/tutorials and sample plugins maintained by the sellers), including multiple plugin types and support for C#, VB.Net, and C++ plugin development. It also includes a “Real Time scripting” feature allowing execution of C# or VB.Net code on compromised systems.
Capabilities described include keylogging, screen capture, password stealing, remote code execution, webcam monitoring, microphone recording, denial of service, reverse proxy, registry exploration/editing, HVNC, and general information stealing. Delivery vectors observed include spearphishing attachments, malicious download links, and drive-by downloads. Anti-analysis features (configurable at build time) include virtual machine detection (ParallelsDesktop, VirtualBox, VirtualPC, VMware) and checks for network monitoring tools (Netmon, TCPView, Wireshark).
The content also notes Orcus distribution via infrastructure previously used in Log4Shell (CVE-2021-44228) exploitation campaigns: Bitdefender observed a server later used to distribute Orcus after being used to deliver a Java class and then a .NET ransomware payload (“Khonsari”) via Log4Shell. The specific URL cited for the Java stage in that campaign is hxxp://3.145.115[.]94/Main.class (same server later used for Orcus distribution). Unit 42 attributes Orcus development/sales to individuals using the aliases “Sorzus” (previously “Alkalinee,” possibly named Vincent) and “Armada,” with Sorzus assessed as the primary developer and Armada handling sales/support.
Reporting
Research mentioning Orcus
New ransomware now being deployed in Log4Shell attacks
In later attacks, BitDefender noticed that this threat actor used the same server to distribute the Orcus Remote Access Trojan.
Imminent Monitor - a RAT Down Under
Palo Alto Networks has collected more than 16,000 distinct samples of Orcus RAT since April 2016... and we have observed more than 46,000 unique attacks using this RAT...
Orcus - Birth of an unusual plugin builder RAT
Unit 42 has been tracking a new Remote Access Trojan (RAT) being sold for $40 USD since April 2016, known as “Orcus”.