Skip to content

RevengeRAT

RevengeRAT is a .NET-based remote access trojan that has been in circulation since at least 2016 and has been widely used by multiple unrelated threat actors after its source code became publicly available.

Profile source: Mallory opens in a new tab

RevengeRAT

Family profile

RevengeRAT is a .NET-based remote access trojan that has been in circulation since at least 2016 and has been widely used by multiple unrelated threat actors after its source code became publicly available. It is commonly deployed as commodity malware in phishing-driven intrusion chains and provides attackers with remote control of compromised Windows systems together with information-theft functionality. Reported use spans criminal campaigns and broader malware distribution operations targeting organizations and individuals worldwide, including government, financial services, information technology, hospitality, tourism, education, energy, pharmaceuticals, transportation, and other sectors.

Observed delivery is primarily through phishing and malspam campaigns using lures such as complaints, invoices, reservations, quotations, and similar business-themed pretexts. Infection chains associated with RevengeRAT have used malicious Office documents, compressed archives, batch scripts, JavaScript, VBScript, PowerShell, and cloud- or paste-hosted staging content. Campaigns have also used obfuscation, steganographic payload retrieval, registry-stored payloads, and multi-stage loaders to hinder analysis and detection.

RevengeRAT functions as a full-featured RAT for post-compromise control and data theft. High-confidence reporting links it to remote administration of victim machines and theft of sensitive information, including credentials and keystrokes in some campaigns. It has also appeared alongside loaders and injectors that execute payloads in memory or through reflective loading, and it has been associated with persistence mechanisms such as Startup-folder execution and recurring script-based relaunch. Some campaigns using RevengeRAT have incorporated process injection, defense evasion, and layered command-and-control obfuscation.

The malware has been observed in operations attributed to or associated with actors such as TA558 and in campaigns documented by Cisco Talos and Morphisec, while other reporting notes possible but low-confidence links between certain RevengeRAT activity and operators of ObliqueRAT. Because leaked-source RATs are frequently modified, infrastructure overlap or code similarity alone is not sufficient for strong attribution. RevengeRAT remains best understood as a broadly reused commodity Windows RAT that is easy for adversaries to customize and embed in diverse phishing-led attack chains.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 7, 2026
Last activity
Sep 11, 2026
Feed role
C2
Host form
4 IP / 3 hostnames

Leading locations

  • US3
  • HK2

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • Hong Kong Communications International Co., Limited1
  • Wowrack.com1
  • XNNET LLC1

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
TA558

Once an attack succeeds, TA558 deploys multiple types of malware on victim machines β€” including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla β€” for remote computer control and information theft.

Aggah

Aggah specifically has been seen using paste.ee to host njRAT, NetWire RAT, RevengeRAT, Agent Tesla.

MITRE ATT&CK

RevengeRAT in ATT&CK

17 distinct techniques

Reporting

Research mentioning RevengeRAT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.