VenomRAT is a commodity Windows remote access trojan used by multiple cybercriminal actors since at least 2020. It is widely assessed as part of the AsyncRAT and DcRat lineage and has also been described as a Quasar RAT-derived clone with substantial added functionality, reflecting the overlap and code reuse common across this ecosystem. VenomRAT provides full remote control of compromised systems and supports arbitrary command execution, information gathering, data exfiltration, lateral movement, and delivery of follow-on payloads. Reported variants and associated tooling have also included credential-stealing features, hidden virtual network computing functionality for covert interactive access, and in some cases ransomware-related capability.
VenomRAT is primarily associated with Windows environments and is commonly delivered through phishing and malspam campaigns, including invoice, tax, and other business-themed lures. Observed delivery chains have used URLs or attachments leading to shortcut, script, batch, or Python-based loaders, sometimes staged through trusted or abused cloud infrastructure and malicious websites. In recent campaigns, VenomRAT has been injected into legitimate Windows processes as part of multi-stage infection chains designed to evade detection.
The malware is used by multiple unrelated threat actors rather than a single exclusive operator. Public reporting has linked prominent distribution activity to TA558 and occasional use to TA2541, while other campaigns have delivered VenomRAT alongside AsyncRAT, XWorm, Remcos, GuLoader, and other commodity malware families. VenomRAT infrastructure has also appeared in broader multi-family criminal hosting environments and was targeted by international law-enforcement disruption activity under Operation Endgame in late 2025. The malware and related Venom-branded tooling have been marketed as remote administration or offensive security software, but their feature set and deployment patterns are consistent with criminal remote access operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)
VenomRAT is a commodity remote access trojan (RAT) used by multiple cybercriminal threat actors. Around since 2020 but first observed in Proofpoint data in 2022... VenomRAT can be used for information gathering, exfiltration, lateral movement, and to download follow-on payloads. Some VenomRAT variants contain ransomware functionality.
VenomRAT is a commodity remote access trojan (RAT) used by multiple cybercriminal threat actors. Around since 2020 but first observed in Proofpoint data in 2022... VenomRAT can be used for information gathering, exfiltration, lateral movement, and to download follow-on payloads. Some VenomRAT variants contain ransomware functionality.
The toolkit includes PureLogs, PureHVNC, and repackaged commodity RATs (AsyncRAT, VenomRAT, DcRat, XWorm).
32 distinct techniques documented for this family, organized by ATT&CK tactic.
T1583.003 — Acquire Infrastructure: Virtual Private Server (Resource Development)
« VenomRAT ». Ce programme malveillant identifié en 2020 était principalement « diffusé via des campagnes d'hameçonnage ou de sites Internet malveillants »
Il est généralement diffusé via des campagnes de phishing, des logiciels piratés, des pièces jointes malveillantes ou encore via l’exploitation des vulnérabilités non corrigées.
Il est généralement diffusé via des campagnes de phishing, des logiciels piratés, des pièces jointes malveillantes ou encore via l’exploitation des vulnérabilités non corrigées.
That subdomain hosts an LNK file, which uses PowerShell to fetch a JavaScript file from the same tunnel.
This batch file is heavily obfuscated and does the real heavy lifting. It opens the fake invoice PDF as a decoy while downloading a second ZIP file that carries a Python package.
When executed, it establishes a connection to an external file share, typically via WebDAV, to download an LNK or VBS file.
When executed, the LNK/VBS executes a BAT or CMD file that downloads a Python installer package and a series of Python scripts leading to malware installation.
The JavaScript, once deobfuscated, quietly pulls down a batch file from the same infrastructure.
allocate RWX memory, write shellcode via WriteProcessMemory ... ctypes.windll.kernel32.VirtualProtect(... 0x40, # PAGE_EXECUTE_READWRITE ... )
This batch file is heavily obfuscated and does the real heavy lifting.
It uses this access to allocate memory, create threads, and copy shellcode into place, all classic building blocks of process injection
The technique used here is Early Bird APC Queue injection. It plants code into a newly created process before that process starts running its main thread
Clicking it downloads a ZIP file containing an internet shortcut, and opening it connects to a TryCloudflare subdomain.
If detected, downloads abb11.zip (OBKS-only, Avast-safe profile). If not, downloads quz11.zip (full WBKS + BKSNO deployment).
Checks for AvastUI.exe and AVGUI.exe via tasklist. If detected, downloads abb11.zip (OBKS-only, Avast-safe profile). If not, downloads quz11.zip
Après infection, le malware procède à la collecte des informations systèmes et utilisateurs...
131 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
61 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VenomRAT2
Remote access trojan delivered as an alternate payload in the same infection chain, injected into notepad.exe by the Python loader.
Fork/descendant in the AsyncRAT family tree, derived through DCRAT lineage.
The disruption is the latest phase of Operation Endgame, which previously disrupted other malware families, such as DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.