RevengeRAT is a .NET-based remote access trojan (RAT) that has been used by multiple adversaries since at least 2016 to attack organizations and individuals worldwide. Its source code was publicly leaked, which has enabled widespread reuse and modification by unrelated threat actors and sustained its prevalence as a commodity/open-source RAT.
Cisco Talos reported campaigns distributing RevengeRAT alongside Orcus RAT, targeting government entities, financial services organizations, and IT service providers/consultancies. In those campaigns, initial access was achieved through phishing emails themed as complaints and impersonating organizations such as the Better Business Bureau (BBB), the Australian Competition & Consumer Commission (ACCC), and New Zealand’s Ministry of Business Innovation & Employment (MBIE). Delivery mechanisms included SendGrid redirect links to attacker-hosted ZIP archives and later ZIP attachments containing malicious batch downloaders. Observed infection chains used double-extension masquerading, SmartAssembly-protected .NET loaders, in-memory execution, and obfuscated batch/JavaScript stages. In one later-stage chain, a batch downloader wrote C:\windows\r2.js, which stored an encoded payload in the Windows registry, decoded it, and executed it; decompilation showed the payload was RevengeRAT. Talos also observed command-and-control obfuscation through DDNS hostnames pointed to the Portmap service, with a Let’s Encrypt TLS certificate on observed infrastructure.
Securonix also described a separate campaign, SERPENTINE#CLOUD, using phishing lures themed as invoices/payments and malicious .lnk files disguised as PDFs. That campaign abused Cloudflare Tunnel subdomains and WebDAV over HTTPS to stage multi-step payload delivery involving WSF/VBScript, heavily obfuscated batch files, bundled Python runtimes, persistence via the Windows Startup folder, and in-memory shellcode execution using Early Bird APC injection and Donut-packed payloads. Securonix assessed the end result as RAT-like access consistent with commodity/open-source families such as AsyncRAT or RevengeRAT, but this payload identification was not definitive.
Talos further noted a low-confidence possible link between certain RevengeRAT campaigns and ObliqueRAT operators. RevengeRAT was mentioned in the context of infrastructure/tooling overlap with ObliqueRAT and CrimsonRAT activity, but the content does not establish firm attribution to a single threat actor.
High-confidence characteristics directly supported by the content are that RevengeRAT is a .NET RAT, publicly leaked, widely reused, delivered in phishing-led campaigns, and associated with obfuscated multi-stage loaders and remote-access functionality. Specific indicators mentioned in connection with campaigns involving or potentially involving RevengeRAT include DDNS-based C2, Portmap-backed infrastructure, Let’s Encrypt certificates, and in one campaign chain the file path C:\windows\r2.js used to decode and execute the RAT payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan capability referenced as a likely final-stage RAT payload delivered by the campaign, enabling full command-and-control and data theft and potential lateral movement.
RevengeRAT is a .NET-based remote access trojan whose source code was leaked publicly. It is used by both crimeware and state-sponsored groups for remote access, data theft, and espionage. There are infrastructure overlaps with ObliqueRAT campaigns.
Remote access trojan with publicly leaked source code; delivered via phishing using ZIP attachments containing batch downloaders and an obfuscated JS stage that stores an encoded payload in the registry, decodes it, and executes it. Campaigns also used DDNS and Portmap to obfuscate C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.