Canadian authorities executed search warrants at a Greater Toronto Area residence as part of a coordinated investigation into Orcus RAT, working with the FBI and Australian Federal Police. The CRTC and RCMP National Division said the case was triggered by tips from private cybersecurity firms and involves parallel investigations into remote access trojan technology used to gain unauthorized access to computers, steal personal information, and deploy additional malware. Reporting identified the location as linked to John "Armada" Revesz, who said investigators seized backup drives containing Orcus Technologies business records, user information, and financial transaction data.
Researchers and law enforcement have long disputed claims that Orcus was a legitimate administration tool, citing capabilities commonly associated with malware, including keylogging, password theft, stealth webcam and microphone access, persistence mechanisms, remote code execution, and DDoS functions. Palo Alto Networks previously described Orcus as a low-cost, modular RAT sold commercially with plugin support, real-time scripting, anti-analysis checks, and delivery options such as spear phishing, malicious links, and drive-by downloads, concluding that it was clearly designed for cybercriminal use despite its marketing.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
On Pastebin, John “Armada” Revesz said his company had been targeted by an international search warrant executed jointly by Canadian authorities. He said backup drives containing Orcus Technologies business data, including user information and financial transactions, were seized.
Canadian authorities publicly announced that the CRTC and RCMP had executed warrants tied to an active malware investigation and said the matter was part of an international coordinated effort. They declined to identify the individuals or companies under investigation because the case was ongoing.
The Canadian Radio-television and Telecommunications Commission and the RCMP National Division each executed a warrant at a residence in the Greater Toronto Area as part of parallel investigations into remote access trojan technology. The coordinated effort involved the FBI and Australian Federal Police and was triggered by tips from private cybersecurity firms.
Fortinet reported that Orcus could use a watchdog to restart its server component if terminated and could trigger a Blue Screen of Death if someone tried to kill its process, adding to evidence of its malware-like behavior.
Palo Alto Networks Unit 42 published research describing Orcus as a modular remote access trojan with plugin support, real-time scripting, anti-analysis features, and capabilities including keylogging, password theft, webcam access, and remote code execution.
Unit 42 reported that Orcus had been sold since April 2016 for about $40 USD, marking its commercial availability to buyers. The sellers were assessed as “Sorzus” handling development and “Armada” handling sales and support.
The developer later associated with the alias “Sorzus” discussed Orcus on a hacker forum around October 2015, during the malware’s early development phase when it was initially named “Schnorchel.”
After the raid, Revesz warned users to move away from Orcus and said it should no longer be considered a safe or secure remote administration solution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourcecanada.ca
Open sourceresearchcenter.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.