ReVBShell is an open-source lightweight VBScript backdoor used in multiple espionage intrusions, including operations attributed to Chinese state-linked threat activity such as Tick and TAG-74/related clusters. It has been deployed as a basic post-compromise implant and also in customized forms integrated into more elaborate intrusion chains.
Observed delivery and execution methods include trojanized software installers, malicious update packages, and spearphishing-delivered compiled HTML Help files that trigger DLL search-order hijacking. In documented campaigns, operators used legitimate signed applications vulnerable to DLL side-loading to launch loaders that decrypted or dropped ReVBShell, and in some cases injected supporting payloads into system processes to maintain execution and persistence.
Its core role is remote backdoor access. Customized variants have supported command execution, configurable beacon sleep intervals, self-deletion, and host reconnaissance through WMI or WMIC-based enumeration. Some variants encoded command-and-control traffic and included simple defensive guardrails intended to avoid execution in the presence of specific security software. ReVBShell has also been associated with persistence mechanisms such as registry-based autorun and with exfiltration over command-and-control channels.
ReVBShell is best characterized as a low-complexity, adaptable backdoor that threat actors reuse as an initial foothold or lightweight access tool, often alongside more capable malware families for broader post-exploitation and long-term espionage objectives. Documented targeting includes government, military-adjacent, political, academic, aerospace, engineering, manufacturing, and other enterprise environments in East Asia, Russia, Georgia, and Mongolia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...trojanized copies that, when executed, dropped an open-source VBScript backdoor named ReVBShell... ReVBShell is an open-source backdoor with very basic capabilities.
TAG-74 used .chm files that trigger a DLL search order hijacking execution chain to load a customized version of the open-source, lightweight, VBScript backdoor ReVBShell.
TAG-74 used .chm files that trigger a DLL search order hijacking execution chain to load a customized version of the open-source, lightweight, VBScript backdoor ReVBShell.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Tick compromised update servers to deliver malicious update packages via the software developed by the compromised company.
Netboy, ShadowPy, and their loader use encrypted: payloads, strings, configuration. Loaders contain garbage code.
"...executes the native HTML Help Windows binary hh.exe to decompile the .chm file..."
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source VBScript backdoor with Python controller code that communicates over HTTP GET/POST and supports host and user discovery, process listing, shell command execution, directory changes, file download, and file upload. In this campaign, customized versions were dropped by trojanized Q-Dir installers and malicious updates.
Publicly available VBS-based web shell/remote shell utility referenced as part of the toolset used by the operators; no additional detail provided in this report.
An open-source VBScript backdoor used for initial access and command execution. In this campaign it was customized to Base64-encode C2 traffic, add execution guardrails (exit if ESET AV is detected), support additional commands (code execution, sleep interval changes, self-deletion), and perform host enumeration via WMIC/WMI.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.