OctoRAT is a .NET-based remote access trojan (RAT) observed as the third-stage payload in a supply-chain attack delivered through the malicious Visual Studio Code extension "prettier-vscode-plus" on the official VSCode Marketplace. In the documented attack chain, a VBScript dropper launched a PowerShell payload containing an AES-encrypted blob, which decrypted and executed the Anivia loader in memory; Anivia then decrypted and injected OctoRAT into the legitimate vbc.exe process using process hollowing. Both Anivia and OctoRAT were reported to use AES-256-CBC with PKCS7 padding for payload protection.
The malware provides full remote access and was described as supporting more than 70 commands. Reported capabilities include surveillance, file theft, remote desktop control, persistence, privilege escalation, harassment functions, and operation of a SOCKS proxy on infected hosts. It targets browser credentials, autofill data, session cookies, and cryptocurrency wallets from Chrome, Firefox, and Edge. OctoRAT was also reported to disable Windows security features such as UAC and Firewall via registry and netsh commands.
For privilege escalation, OctoRAT uses the FodHelper UAC bypass technique and deletes registry traces afterward. Persistence was reported via a scheduled task named "WindowsUpdate" configured to run every minute. C2 communications include heartbeat mechanisms, robust error handling, and JSON-formatted reconnaissance packets. The default C2 configuration reportedly includes 127.0.0[.]1:8080, likely for development or testing. Internet-wide scanning identified at least seven active OctoRAT C2 panels, including 178.16.55[.]109 and 51.178.245[.]127. The panel is fingerprintable by the HTML title "OctoRAT Center - Login," and infrastructure analysis linked multiple panels to Railnet LLC hosting, with certificate reuse across servers in Germany and the Netherlands.
The malware was associated with a late-November 2025 campaign targeting developers through the VSCode extension ecosystem. The malicious extension impersonated the legitimate Prettier formatter, was published under the account "publishingsofficial," and remained available for roughly four hours before removal. Reported detection opportunities include monitoring for the "prettier-vscode-plus" extension, suspicious GitHub access used for payload hosting and rotation, vbc.exe process hollowing, and OctoRAT Center panel fingerprints. The campaign was analyzed by Checkmarx Zero and Hunt Intelligence, Inc.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used for surveillance, file theft, and remote control; also harvests browser credentials from Chrome, Firefox, and Edge prior to C2 communication.
OctoRAT is a remote access trojan with extensive capabilities for surveillance, file theft, remote desktop, persistence, privilege escalation, and harassment.
OctoRAT is a fully featured remote access trojan (RAT) written in .NET, offering over 70 command modules for surveillance, file theft, remote desktop control, persistence, privilege escalation, credential and cryptocurrency wallet theft, and harassment. It uses process hollowing, AES-encrypted payloads, and robust C2 infrastructure. It is likely distributed as Malware-as-a-Service (MaaS) and targets developers via supply-chain attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.