Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 28, 2026
- Feed role
- C2
- Host form
- 0 IP / 11 hostnames
RevengeRAT is a .NET-based remote access trojan (RAT) that has been used by multiple adversaries since at least 2016 to attack organizations and individuals worldwide.
Profile source: Mallory opens in a new tabRevengeRAT
RevengeRAT is a .NET-based remote access trojan (RAT) that has been used by multiple adversaries since at least 2016 to attack organizations and individuals worldwide. Its source code was publicly leaked, which has enabled widespread reuse and modification by unrelated threat actors and sustained its prevalence as a commodity/open-source RAT.
Cisco Talos reported campaigns distributing RevengeRAT alongside Orcus RAT, targeting government entities, financial services organizations, and IT service providers/consultancies. In those campaigns, initial access was achieved through phishing emails themed as complaints and impersonating organizations such as the Better Business Bureau (BBB), the Australian Competition & Consumer Commission (ACCC), and New Zealand’s Ministry of Business Innovation & Employment (MBIE). Delivery mechanisms included SendGrid redirect links to attacker-hosted ZIP archives and later ZIP attachments containing malicious batch downloaders. Observed infection chains used double-extension masquerading, SmartAssembly-protected .NET loaders, in-memory execution, and obfuscated batch/JavaScript stages. In one later-stage chain, a batch downloader wrote C:\windows\r2.js, which stored an encoded payload in the Windows registry, decoded it, and executed it; decompilation showed the payload was RevengeRAT. Talos also observed command-and-control obfuscation through DDNS hostnames pointed to the Portmap service, with a Let’s Encrypt TLS certificate on observed infrastructure.
Securonix also described a separate campaign, SERPENTINE#CLOUD, using phishing lures themed as invoices/payments and malicious .lnk files disguised as PDFs. That campaign abused Cloudflare Tunnel subdomains and WebDAV over HTTPS to stage multi-step payload delivery involving WSF/VBScript, heavily obfuscated batch files, bundled Python runtimes, persistence via the Windows Startup folder, and in-memory shellcode execution using Early Bird APC injection and Donut-packed payloads. Securonix assessed the end result as RAT-like access consistent with commodity/open-source families such as AsyncRAT or RevengeRAT, but this payload identification was not definitive.
Talos further noted a low-confidence possible link between certain RevengeRAT campaigns and ObliqueRAT operators. RevengeRAT was mentioned in the context of infrastructure/tooling overlap with ObliqueRAT and CrimsonRAT activity, but the content does not establish firm attribution to a single threat actor.
High-confidence characteristics directly supported by the content are that RevengeRAT is a .NET RAT, publicly leaked, widely reused, delivered in phishing-led campaigns, and associated with obfuscated multi-stage loaders and remote-access functionality. Specific indicators mentioned in connection with campaigns involving or potentially involving RevengeRAT include DDNS-based C2, Portmap-backed infrastructure, Let’s Encrypt certificates, and in one campaign chain the file path C:\windows\r2.js used to decode and execute the RAT payload.
C2 tracking
Derp observations, rolling seven-day window
Samples
453b626c5ac3ca80cab562354e4c94be0b53749a18f567c575c4e1bd8d14d2e9 a60045ad62c813e59339c41cdb5806777c2efc670e13ee8dc190f28a30c99920 be0e8cbfbe695051c3374e8afcece477361d5c4062fd241124ddd5495f1779fd 3524629ecb39966525ac83d45f487ca0c2c694d8c6d45826291d3ec2366f9997 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 efffbda36edcb7d4130f65a57d3966e7694172fb5db37ce48f27849d239066c7 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.