Last seven days
- First activity
- Sep 7, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2
- Host form
- 4 IP / 3 hostnames
RevengeRAT is a .NET-based remote access trojan that has been in circulation since at least 2016 and has been widely used by multiple unrelated threat actors after its source code became publicly available.
Profile source: Mallory opens in a new tabRevengeRAT
RevengeRAT is a .NET-based remote access trojan that has been in circulation since at least 2016 and has been widely used by multiple unrelated threat actors after its source code became publicly available. It is commonly deployed as commodity malware in phishing-driven intrusion chains and provides attackers with remote control of compromised Windows systems together with information-theft functionality. Reported use spans criminal campaigns and broader malware distribution operations targeting organizations and individuals worldwide, including government, financial services, information technology, hospitality, tourism, education, energy, pharmaceuticals, transportation, and other sectors.
Observed delivery is primarily through phishing and malspam campaigns using lures such as complaints, invoices, reservations, quotations, and similar business-themed pretexts. Infection chains associated with RevengeRAT have used malicious Office documents, compressed archives, batch scripts, JavaScript, VBScript, PowerShell, and cloud- or paste-hosted staging content. Campaigns have also used obfuscation, steganographic payload retrieval, registry-stored payloads, and multi-stage loaders to hinder analysis and detection.
RevengeRAT functions as a full-featured RAT for post-compromise control and data theft. High-confidence reporting links it to remote administration of victim machines and theft of sensitive information, including credentials and keystrokes in some campaigns. It has also appeared alongside loaders and injectors that execute payloads in memory or through reflective loading, and it has been associated with persistence mechanisms such as Startup-folder execution and recurring script-based relaunch. Some campaigns using RevengeRAT have incorporated process injection, defense evasion, and layered command-and-control obfuscation.
The malware has been observed in operations attributed to or associated with actors such as TA558 and in campaigns documented by Cisco Talos and Morphisec, while other reporting notes possible but low-confidence links between certain RevengeRAT activity and operators of ObliqueRAT. Because leaked-source RATs are frequently modified, infrastructure overlap or code similarity alone is not sufficient for strong attribution. RevengeRAT remains best understood as a broadly reused commodity Windows RAT that is easy for adversaries to customize and embed in diverse phishing-led attack chains.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e c2e9fbca414575d5c080d97f378024a4d131d6e1262112aebaa96eafa3592381 9b23fb08028ff95310767ba7c383627c8ec08c52c8e7661f1f0fd1524c34a458 a5d6d65f6ddb61aa0906c74604cc0a2791ee23d5990737e8819fb6458be870d5 1d7d4e4ef6fce187d454939bb957b56cabfaab9e156c87fe9c432a5bcd3949d3 28ecb0b42af2149af0b65bcf1d368f7d33d76212bc9d195eb4071779574b3845 Reported operators
Once an attack succeeds, TA558 deploys multiple types of malware on victim machines β including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla β for remote computer control and information theft.
Aggah specifically has been seen using paste.ee to host njRAT, NetWire RAT, RevengeRAT, Agent Tesla.
MITRE ATT&CK
Reporting
Threat actors distributed Orcus RAT and RevengeRAT through phishing emails masquerading as official complaints, using delivery methods that shifted from SendGrid-linked downloads to ZIP archives containing malicious batch files and script-based payloads. Reporting tied the activity to organizations worldwide, including government, financial services, IT services, and consulting sectors, and linked both malware families to the same client identifier, CORREOS, suggesting shared campaign infrastructure or operator overlap. Technical analysis showed heavily obfuscated infection chains built around VBS, batch, and PowerShell components, with payloads hidden in byte arrays, registry data, or protected loaders and then injected in memory using RunPE/process hollowing into legitimate processes such as InstallUtil.exe. Researchers also observed persistence through Startup shortcuts and recurring batch execution, along with command-and-control concealment using DDNS and Portmap services; one analyzed RevengeRAT sample communicated with h0pe1759.ddns.net and retained common remote-access features including screenshot capture, system profiling, and antivirus enumeration.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.