Skip to content

RevengeRAT

RevengeRAT is a .NET-based remote access trojan (RAT) that has been used by multiple adversaries since at least 2016 to attack organizations and individuals worldwide.

Profile source: Mallory opens in a new tab

RevengeRAT

Family profile

RevengeRAT is a .NET-based remote access trojan (RAT) that has been used by multiple adversaries since at least 2016 to attack organizations and individuals worldwide. Its source code was publicly leaked, which has enabled widespread reuse and modification by unrelated threat actors and sustained its prevalence as a commodity/open-source RAT.

Cisco Talos reported campaigns distributing RevengeRAT alongside Orcus RAT, targeting government entities, financial services organizations, and IT service providers/consultancies. In those campaigns, initial access was achieved through phishing emails themed as complaints and impersonating organizations such as the Better Business Bureau (BBB), the Australian Competition & Consumer Commission (ACCC), and New Zealand’s Ministry of Business Innovation & Employment (MBIE). Delivery mechanisms included SendGrid redirect links to attacker-hosted ZIP archives and later ZIP attachments containing malicious batch downloaders. Observed infection chains used double-extension masquerading, SmartAssembly-protected .NET loaders, in-memory execution, and obfuscated batch/JavaScript stages. In one later-stage chain, a batch downloader wrote C:\windows\r2.js, which stored an encoded payload in the Windows registry, decoded it, and executed it; decompilation showed the payload was RevengeRAT. Talos also observed command-and-control obfuscation through DDNS hostnames pointed to the Portmap service, with a Let’s Encrypt TLS certificate on observed infrastructure.

Securonix also described a separate campaign, SERPENTINE#CLOUD, using phishing lures themed as invoices/payments and malicious .lnk files disguised as PDFs. That campaign abused Cloudflare Tunnel subdomains and WebDAV over HTTPS to stage multi-step payload delivery involving WSF/VBScript, heavily obfuscated batch files, bundled Python runtimes, persistence via the Windows Startup folder, and in-memory shellcode execution using Early Bird APC injection and Donut-packed payloads. Securonix assessed the end result as RAT-like access consistent with commodity/open-source families such as AsyncRAT or RevengeRAT, but this payload identification was not definitive.

Talos further noted a low-confidence possible link between certain RevengeRAT campaigns and ObliqueRAT operators. RevengeRAT was mentioned in the context of infrastructure/tooling overlap with ObliqueRAT and CrimsonRAT activity, but the content does not establish firm attribution to a single threat actor.

High-confidence characteristics directly supported by the content are that RevengeRAT is a .NET RAT, publicly leaked, widely reused, delivered in phishing-led campaigns, and associated with obfuscated multi-stage loaders and remote-access functionality. Specific indicators mentioned in connection with campaigns involving or potentially involving RevengeRAT include DDNS-based C2, Portmap-backed infrastructure, Let’s Encrypt certificates, and in one campaign chain the file path C:\windows\r2.js used to decode and execute the RAT payload.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 28, 2026
Feed role
C2
Host form
0 IP / 11 hostnames

Leading locations

  • US4
  • CO1
  • DE1

Leading providers

  • EdgeUno2
  • Wowrack.com2
  • EDGEUNO S.A.S1
  • Ferdinand Zink trading as Tube-Hosting1

Infrastructure traits

  • Hosting 5
  • Residential Proxy 1

Samples

Recent associated samples

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.