Orcus is a commercially sold, feature-rich Remote Access Trojan (RAT) written in C# (with a WPF-based Windows controller UI) and marketed since April 2016 for about $40. It uses a three-component architecture—controller (admin panel), server, and victim trojan—where infected hosts connect back to an Orcus server rather than directly to the operator’s controller, enabling shared access among multiple criminals and scalable deployments across multiple servers. Orcus is modular and supports custom plugins (with documented developer packages/tutorials and sample plugins maintained by the sellers), including multiple plugin types and support for C#, VB.Net, and C++ plugin development. It also includes a “Real Time scripting” feature allowing execution of C# or VB.Net code on compromised systems.
Capabilities described include keylogging, screen capture, password stealing, remote code execution, webcam monitoring, microphone recording, denial of service, reverse proxy, registry exploration/editing, HVNC, and general information stealing. Delivery vectors observed include spearphishing attachments, malicious download links, and drive-by downloads. Anti-analysis features (configurable at build time) include virtual machine detection (ParallelsDesktop, VirtualBox, VirtualPC, VMware) and checks for network monitoring tools (Netmon, TCPView, Wireshark).
The content also notes Orcus distribution via infrastructure previously used in Log4Shell (CVE-2021-44228) exploitation campaigns: Bitdefender observed a server later used to distribute Orcus after being used to deliver a Java class and then a .NET ransomware payload (“Khonsari”) via Log4Shell. The specific URL cited for the Java stage in that campaign is hxxp://3.145.115[.]94/Main.class (same server later used for Orcus distribution). Unit 42 attributes Orcus development/sales to individuals using the aliases “Sorzus” (previously “Alkalinee,” possibly named Vincent) and “Armada,” with Sorzus assessed as the primary developer and Armada handling sales/support.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan distributed from the same infrastructure used in the Log4Shell-delivered Khonsari campaign, enabling remote control of infected systems.
A commodity remote access trojan/tool used in large volumes of attacks; discussed in the context of law-enforcement action against its operators and customers.
Commercially sold modular RAT written in C#/.NET with a separate controller and server architecture. Provides full remote control of infected Windows hosts (keylogging, screengrabs, remote code execution, webcam/mic monitoring, password stealing, reverse proxy, HVNC, DoS, registry editing) and supports an advanced plugin system plus real-time scripting. Includes anti-analysis features such as VM detection (Parallels, VirtualBox, VirtualPC, VMware) and checks for network monitoring tools (Netmon, TCPView, Wireshark).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.