Orcus is a commercially sold, modular remote access Trojan first observed in 2016 and marketed as a remote administration tool, but widely assessed as malware due to its surveillance, credential theft, and remote control capabilities. It is implemented in C# and uses a multi-component architecture consisting of a controller, a server, and a victim-side payload. This separation allows infected systems to connect to an intermediary server rather than directly to an operator console, enabling scalable operations and shared access among multiple operators.
Orcus supports a broad range of post-compromise functions, including keylogging, password theft, screen capture, webcam and microphone surveillance, remote code execution, registry browsing and editing, reverse proxying, hidden virtual network computing, and extensibility through custom plugins. It also includes real-time scripting that allows operators to execute C# or VB.Net code on compromised hosts. Anti-analysis features include optional checks for virtualized environments and for common network monitoring tools, supporting defense evasion.
Observed delivery methods include spearphishing attachments, malicious download links, and drive-by download activity. Orcus has been associated with cybercriminal use rather than legitimate administration, and reporting has linked its development and commercialization to the aliases Sorzus and Armada, with Sorzus assessed as the principal developer and Armada associated with sales and support. Orcus has also appeared as a payload in broader exploitation activity, including campaigns leveraging Log4Shell. The malware primarily targets Windows systems, while an Android application has been used as an operator-side controller rather than as the victim payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The initial remote code execution vulnerability (CVE-2021-44228) has been dubbed Log4Shell... The vulnerability has been exploited to deploy a plethora of payloads like coin miners, Dridex malware, and even ransomware such as Conti. | Other publicly reported payloads include the Khonsari and Conti ransomware threats, the Orcus remote access Trojan (RAT), and the Dridex malware, among others.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
If an Orcus user enables the VMDetection feature while building the malware binary, the malware would check if the malware is running within a virtual machine environment. The virtual machines that Orcus detects are ParallelsDesktop, VirtualBox, VirtualPC and VMWare.
If an Orcus user enables the VMDetection feature while building the malware binary, the malware would check if the malware is running within a virtual machine environment. The virtual machines that Orcus detects are ParallelsDesktop, VirtualBox, VirtualPC and VMWare.
Below are some Orcus features that can enable full control of a victim machine: Keylogger
Below are some Orcus features that can enable full control of a victim machine: Keylogger Screengrabs
if a victim machine is infected with an Orcus RAT, it connects back to the Orcus server which does not have the admin panel on it. Orcus has a separate component for the admin panel (Orcus controller) which enables control of all infected machines from the Orcus controller.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan publicly reported as a payload associated with Log4Shell exploitation.
Remote access trojan distributed from the same infrastructure used in the Log4Shell-delivered Khonsari campaign, enabling remote control of infected systems.
A commodity remote access trojan/tool used in large volumes of attacks; discussed in the context of law-enforcement action against its operators and customers.
Commercially sold modular RAT written in C#/.NET with a separate controller and server architecture. Provides full remote control of infected Windows hosts (keylogging, screengrabs, remote code execution, webcam/mic monitoring, password stealing, reverse proxy, HVNC, DoS, registry editing) and supports an advanced plugin system plus real-time scripting. Includes anti-analysis features such as VM detection (Parallels, VirtualBox, VirtualPC, VMware) and checks for network monitoring tools (Netmon, TCPView, Wireshark).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.