WebMonitor RAT is a Windows remote access trojan associated with criminal malware-as-a-service activity and marketed with web-based command-and-control capabilities. It has been discussed alongside BitRAT and presented as part of a C2-as-a-service offering, indicating an operator model in which customers can manage infections through hosted infrastructure rather than maintaining their own backend. The malware is positioned as a commodity RAT intended for unauthorized remote control of victim systems.
High-confidence reporting in the available material supports its identification as a RAT, but does not provide a reliable, detailed capability set specific to WebMonitor RAT itself beyond its remote-access role and hosted C2 model. The references indicate overlap in discussion with BitRAT-related activity, but they do not establish that WebMonitor RAT shares BitRAT's full feature set or delivery methods. Likewise, the available material does not provide sufficiently specific, corroborated information on targeted sectors, victim geography, or distinct infection vectors for WebMonitor RAT alone.
WebMonitor RAT is best understood as a commodity Windows RAT offered in a service-oriented criminal ecosystem, with emphasis on browser-accessible or web-managed command-and-control infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
“[#1 Web RAT, CONTROL FROM WEB BROWSER, No PORTFORWARD, KEYLOGGER, + VPN]”
posts an exhaustive list of credentials that this RAT can recover “ Here is a list of what kind of credentials RevCode is capable of recovering ”: Web Browsers... IM Clients... Email Clients... Windows Network Credentials... Protected Storage... Network Credentials...
A list of features is provided at the site... Process manager ... Windows list
WebMonitor offers Command-and-Control (C2)-as-a-Service (C2aas). Customers don’t have to (in fact, can’t) run their own C2 system, it’s provided for them. WebMonitor C2s to virtual-hostnames, apparently unique to each customer, at one of two root C2 domains. Although C2 communication is over HTTPS...
Although C2 communication is over HTTPS, an obvious downside to such a C2 domain architecture is that the C2 traffic is easily detected and blocked based upon the domains.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BitRAT pt. 2: Hidden Browser, SOCKS5 proxy, and UnknownProducts Unmasked BitRAT WebMonitor RAT
Referenced as an earlier RAT offering web-based C2-as-a-service.
Referenced only as the title of the next article.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.