VenomRAT is a remote access trojan associated with cybercrime activity and malware-service infrastructure. It has been identified alongside other criminal malware ecosystems such as Rhadamanthys and the Elysium botnet in multinational law-enforcement disruption efforts, including Operation Endgame. In 2025, authorities seized or disabled infrastructure supporting VenomRAT operations, and the malware's administrator was arrested in Greece. The available information directly supports VenomRAT as a malware operation used for unauthorized remote access and post-compromise control, but does not provide high-confidence detail on specific victim sectors, countries targeted, or a broader actor structure beyond the named malware operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VenomRAT is a remote access trojan used for credential theft, remote access, and supporting botnet operations.
VenomRAT is a remote access trojan used by cybercriminals to gain unauthorized access to victim systems, often as part of broader cybercrime operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.