VenomRAT is a Windows-focused .NET remote access trojan in the AsyncRAT/DcRAT lineage. It provides remote control of compromised systems, hidden virtual network computing, data-stealing and file-grabbing functionality, and can execute commands received from its operator. Observed builds include keylogging, host and hardware discovery, webcam-device enumeration, and collection and transmission of victim-system information. VenomRAT incorporates anti-analysis and defense-evasion functionality, including virtual-machine and server-system checks, dynamic Windows API resolution, in-memory AMSI and ETW tampering, and monitoring-process termination. It has been delivered in phishing campaigns using tax-themed disk-image attachments and DLL sideloading to execute the payload in memory. Such activity has targeted Indian entities and has been assessed as China-nexus financially motivated crimeware, though a conclusive attribution to Silver Fox has not been established. VenomRAT has also been distributed alongside other remote access trojans through phishing chains and has been subject to Operation Endgame infrastructure disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Final Payload: VenomRAT” ... “Venom RAT + HVNC + Stealer + Grabber v6.0.3.”
This comparison explores the core technical differences between VenomRAT and AsyncRAT by analyzing their architecture, capabilities, and tactics.
This comparison explores the core technical differences between VenomRAT and AsyncRAT by analyzing their architecture, capabilities, and tactics.
This comparison explores the core technical differences between VenomRAT and AsyncRAT by analyzing their architecture, capabilities, and tactics.
This comparison explores the core technical differences between VenomRAT and AsyncRAT by analyzing their architecture, capabilities, and tactics.
DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The operator used a believable tax-related lure and contained a seemingly routine attachment... Tax_Notice_45594.img. | Files carried inside a mounted ISO do not inherit Mark-of-the-Web... the Tax_Notice_45594.exe inside comes out clean – no MOTW, so SmartScreen and the Office/Explorer downloaded-from-the-internet warnings never fire.
apc_run_payload – the APC callback that eventually executes the decrypted shellcode... The APC callback is responsible for executing the decrypted payload in memory.
Then three passes over the body – ^= xor1, bitwise NOT, ^= xor2 followed by a DWORD level Fisher–Yates de-shuffle and finally RC4 with the 16-byte key applied.
Dynamic API Resolution ✔ DInvokeCore class for dynamic API resolution T1027.007 ✘ Not implemented
The last 26 bytes of the file are a parameter block... three passes over the body – xor, bitwise NOT, xor – followed by a DWORD level Fisher–Yates de-shuffle and finally RC4.
Every section has been deliberately named to suggest it contains something else entirely... the section named .pdata is the import table.
Install directory %APPDATA%\Microsoft\Crypto\RuntimeBroker\... Masquerade RuntimeBroker.exe (impersonates Windows Runtime Broker).
“This technique can strip the internet-origin mark from the files inside, reducing the warnings Windows would normally display.”
Check Constant Fails if CPU cores <= 1... Physical RAM... Free disk... Uptime... Cursor moved... Screen resolution... Last user input.
Check Constant Fails if CPU cores <= 1... Physical RAM... Free disk... Cursor moved... Screen resolution... Last user input.
Process discovery ✔ This the capability to obtain a listing of running processes T1057 ✘ Not implemented
Check Constant Fails if CPU cores <= 1... Physical RAM... Free disk... Uptime... Cursor moved... Screen resolution... Last user input.
172 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
72 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET remote-access trojan delivered through DLL sideloading of a signed, renamed Notepad++ executable. It provides remote command execution, hidden VNC, data theft, and file-grabbing capabilities, with a configured C2 server at 154.36.188.201:4449.
A .NET remote-access trojan deployed as the final payload. This v6.0.3 build communicates with 154.36.188.201:4449 and includes RAT, hidden virtual network computing (HVNC), credential/data-stealing, and grabber capabilities. Its configuration includes a mutex and can support process-critical anti-kill behavior, although the anti-kill option is disabled in this sample.
A .NET remote-access trojan delivered as the final payload. This build supports remote command-and-control, HVNC, credential/data stealing, and grabbing capabilities; it includes D/Invoke-based hooked-API bypass functionality and can optionally make its process critical. The preceding loader handles elevation, persistence, and anti-analysis.
A .NET remote-access trojan delivered as the final payload. This build provides C2, HVNC, credential/data-stealing and grabber capabilities; it can also terminate its HVNC worker processes and includes optional process-critical anti-kill functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.