Threat actors distributed Orcus RAT and RevengeRAT through phishing emails masquerading as official complaints, using delivery methods that shifted from SendGrid-linked downloads to ZIP archives containing malicious batch files and script-based payloads. Reporting tied the activity to organizations worldwide, including government, financial services, IT services, and consulting sectors, and linked both malware families to the same client identifier, CORREOS, suggesting shared campaign infrastructure or operator overlap.
Technical analysis showed heavily obfuscated infection chains built around VBS, batch, and PowerShell components, with payloads hidden in byte arrays, registry data, or protected loaders and then injected in memory using RunPE/process hollowing into legitimate processes such as InstallUtil.exe. Researchers also observed persistence through Startup shortcuts and recurring batch execution, along with command-and-control concealment using DDNS and Portmap services; one analyzed RevengeRAT sample communicated with h0pe1759.ddns.net and retained common remote-access features including screenshot capture, system profiling, and antivirus enumeration.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
A malware analysis write-up described a suspicious email linking to a OneDrive-hosted VBS script that launched additional components and ultimately delivered Revenge RAT. The analysis identified process hollowing into InstallUtil.exe and a command-and-control server at h0pe1759.ddns.net.
Talos observed the actor evolve its delivery chain from emails containing SendGrid-linked downloads to phishing emails with ZIP attachments. The later attachments contained obfuscated batch files that retrieved and executed malware, eventually leading to RevengeRAT.
Cisco Talos reported malware distribution campaigns in which a threat actor used complaint-themed phishing emails impersonating authorities to target organizations worldwide with Orcus RAT and RevengeRAT. The campaigns affected government entities, financial services organizations, IT service providers, and consultancies.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcegithub.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.