Violet RAT is a Windows-focused .NET remote-access trojan, including variants that identify themselves as Violet v6. It implements a large command-dispatch capability, reported as supporting approximately 120 commands, enabling operator-directed post-compromise activity. Violet RAT has been deployed alongside other remote-access and information-stealing malware in the SERPENTINE#CLOUD campaign, whose delivery infrastructure used staged batch and Python loaders, in-memory .NET execution, and anti-analysis measures. It has also been observed in a phishing campaign targeting Canadian organizations, where invoice-themed lures and WebDAV-hosted staging content led to a Violet RAT payload. The malware was used as one of several redundant remote-access channels within these operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
[The script] registers the scheduled task wupd_chk to execute every 30 minutes.
Once executed, get.js copies several campaign components... The JavaScript then launches g.bat... Systems that do not match these checks follow a PowerShell based execution path... [other systems] execute the 64-bit AS branch through w.py.
The JavaScript then launches g.bat with the arguments general x while suppressing the visible command window.
If one of the monitored third-party security products is present, the script can deploy an embedded Python runtime and execute the 64-bit AS branch through w.py.
The retrieved WSH configuration references... get.js, which points to the JavaScript responsible for delivering the next stage.
allocate RWX memory, write shellcode via WriteProcessMemory ... ctypes.windll.kernel32.VirtualProtect(... 0x40, # PAGE_EXECUTE_READWRITE ... )
[The script] registers the scheduled task wupd_chk to execute every 30 minutes.
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread.
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread... Instead of notepad.exe, the loaders now create a suspended explorer.exe and use Early Bird APC injection
Wave 4/5 introduces the deepest nesting observed in the campaign. The Nov19 Donut instances deliver native x64 PE wrappers instead of .NET assemblies directly... Layer 2: Kramer decode (hex -> unicode shift -> rotation -> RC4 -> base64)
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread.
Injection technique: create a suspended notepad.exe , allocate RWX memory, write shellcode via WriteProcessMemory , queue an APC, resume the thread... Instead of notepad.exe, the loaders now create a suspended explorer.exe and use Early Bird APC injection
If detected, downloads abb11.zip (OBKS-only, Avast-safe profile). If not, downloads quz11.zip (full WBKS + BKSNO deployment).
Checks for AvastUI.exe and AVGUI.exe via tasklist. If detected, downloads abb11.zip (OBKS-only, Avast-safe profile). If not, downloads quz11.zip
g.bat enumerates running processes and checks for products associated with ESET, Kaspersky, AVG, Avira, and Avast.
If detected, downloads abb11.zip (OBKS-only, Avast-safe profile). If not, downloads quz11.zip (full WBKS + BKSNO deployment).
The shortcut... uses Windows WebDAV syntax to retrieve a remote get.wsh configuration file... additional components can be retrieved and staged remotely. | The infection chain used a document themed lure to move victims into attacker controlled staging infrastructure... it uses Windows WebDAV syntax to retrieve a remote get.wsh configuration file.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET remote-access trojan deployed as the AS branch of the framework. It supplies a separate fallback C2 channel at 91.219.239[.]10:4452.
See also: Violet RAT analysis
A RAT payload family repeatedly delivered via the campaign’s Python->Donut->.NET chain; described as a 120-command dispatcher.
Named as a related payload in the same breach-analysis series; no additional technical details provided in this content beyond being part of the broader campaign context.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.