Revcode is the handle of a cybercriminal malware seller associated with the development, marketing, and operation of WebMonitor, a commodity remote access trojan active since 2017. Revcode advertised WebMonitor on underground forums and operated a hosted sales and support service around the malware. WebMonitor was offered as a low-cost, hosted malware service rather than a standalone toolset. Its operator provided a web-based command-and-control environment and did not allow customers to run independent infrastructure, indicating a centralized malware-as-a-service model. The malware’s Windows client was implemented in Visual Basic 6, commonly packed, and configured for user-level persistence through Windows Run-key autostart mechanisms. Builder options supported startup execution and process restart behavior, reflecting a focus on durable access to compromised hosts. Operationally, WebMonitor used HTTPS for command-and-control communications and customer-specific virtual hostnames under operator-controlled root domains. Later variants introduced repeated DNS lookups for non-existent domains, assessed as either camouflage for command-and-control activity or an unrealized domain-generation-style mechanism. One observed sample also contacted a Monero mining pool, but that behavior was seen only once and is not sufficient to characterize Revcode primarily as a cryptomining actor. The actor appears to have maintained a modest customer base while enabling broad malicious activity through downstream users. WebMonitor infections were observed globally across multiple industry verticals, consistent with indiscriminate commodity malware distribution rather than narrowly targeted espionage. High-confidence reporting links the infrastructure registration to an individual in Bavaria, Germany. A related associate identified as Softpatch was connected to an Android RAT offering tied to the broader WebMonitor ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.