RevC2 is a backdoor/remote access malware family associated with the Golden Chickens (also known as Venom Spider) malware-as-a-service ecosystem. Zscaler ThreatLabz reported it in campaigns observed between August and October 2024, where it was delivered via VenomLNK social-engineering lures, including an API documentation-themed lure. In the observed chain, a VenomLNK file containing an obfuscated BAT script led to regsvr32 execution and loading of a malicious OCX payload. ThreatLabz stated RevC2 was named from the PDB path C:\Users\PC\Desktop\C2New\Rev\x64\Release\Rev.pdb.
RevC2 uses WebSockets for command-and-control communication, including use of the C++ websocketpp library. Reported C2 infrastructure included ws://208.85.17[.]52:8082 and ws://nopsec.org:8082. It registers infected hosts with a JSON object containing the computer name and type value 0005, and creates log files in C:\ProgramData\boot_%YYYYMMDDTHHMMSS%.log. The malware only executes when its first argument ends with dWin.ocx and the current process path matches regsvr32.exe.
Its capabilities include remote code execution, shell command execution with output returned to C2, execution of commands as another user when provided credentials, screenshot capture with base64 encoding, SOCKS5 proxying of network traffic, and theft of saved Chromium passwords and cookies. The reporting characterizes RevC2 as an information-stealing backdoor enabling stealthy persistence and multi-faceted espionage and credential theft within compromised networks.
RevC2 is described as related to other Golden Chickens malware families including Venom Loader, VenomLNK, TerraLoader, TerraStealer, TerraTV, TerraCrypt, TerraRecon, TerraWiper, and lite_more_eggs. ThreatLabz assessed RevC2 as a newly identified family and suggested these Golden Chickens tools appeared to be early versions likely to gain additional features and anti-analysis capabilities over time.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Between August and October 2024, ThreatLabz uncovered campaigns that leveraged two new malware families – RevC2 and Venom Loader... RevC2 uses WebSockets to communicate with its command-and-control (C2) server. The malware is capable of stealing cookies and passwords, proxies network traffic, and enables remote code execution (RCE).
"E. RevC2 Remote access backdoor, enabling stealthy persistence within compromised networks."
"E. RevC2 Remote access backdoor, enabling stealthy persistence within compromised networks."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing backdoor associated with the More_eggs MaaS ecosystem.
"Related Families: VenomLNK, TerraLoader, TerraStealer, TerraTV, TerraCrypt, TerraRecon, TerraWiper, lite_more_eggs, RevC2, Venom Loader"
RevC2 is a backdoor developed by Golden Chickens, featuring WebSocket-based command and control, remote code execution, credential and cookie theft, screenshot capture, and network proxying. It is used for espionage and credential theft in targeted attacks.
Remote access backdoor providing persistence and post-exploitation capabilities including command execution and lateral movement within corporate networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.