VenomRAT is a Windows remote access trojan written in C# for the .NET Framework. It belongs to the AsyncRAT and DcRAT lineage, with shared ancestry in QuasarRAT. Its capabilities include remote command execution, keylogging, system reconnaissance, data theft, and file collection. Version 6.0.3 builds include hidden virtual network computing, enabling covert remote interaction with compromised systems. Its keylogger records process names and window titles and periodically transmits captured keystrokes to command-and-control infrastructure.
VenomRAT collects hardware details, installed application information, and running-process information. Analyzed implementations include virtualization checks, webcam-device enumeration, and termination of selected security, monitoring, and system-management processes. Defense-evasion features include dynamic Windows API resolution and in-memory patching of AMSI and ETW functions. Configuration data is encrypted, and related builds frequently retain inherited TLS certificate metadata.
VenomRAT has been deployed through phishing campaigns using tax notices, invoices, and malicious PDFs that abuse Foxit PDF Reader launch prompts. The PAPERMILL activity cluster uses Indian tax-themed disk-image attachments and a legitimately signed Notepad++ executable to sideload a malicious proxy DLL. This separate loader performs anti-analysis checks, requests elevation, establishes persistence, and uses Donut shellcode to load the VenomRAT payload in memory. Other delivery chains use Python loaders and Early Bird APC injection to execute VenomRAT inside a legitimate Windows process. PAPERMILL is associated with attacks on Indian entities, but a definitive attribution to Silver Fox has not been established. VenomRAT infrastructure was also disrupted through Operation Endgame.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The recovered configuration identifies VenomRAT version 6.0.3 with hidden virtual network computing, data-stealing and file-grabbing capabilities.
This comparison explores the core technical differences between VenomRAT and AsyncRAT by analyzing their architecture, capabilities, and tactics.
This comparison explores the core technical differences between VenomRAT and AsyncRAT by analyzing their architecture, capabilities, and tactics.
This comparison explores the core technical differences between VenomRAT and AsyncRAT by analyzing their architecture, capabilities, and tactics.
This comparison explores the core technical differences between VenomRAT and AsyncRAT by analyzing their architecture, capabilities, and tactics.
DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The operator used a believable tax-related lure and contained a seemingly routine attachment... Tax_Notice_45594.img. | Files carried inside a mounted ISO do not inherit Mark-of-the-Web... the Tax_Notice_45594.exe inside comes out clean – no MOTW, so SmartScreen and the Office/Explorer downloaded-from-the-internet warnings never fire.
apc_run_payload – the APC callback that eventually executes the decrypted shellcode... The APC callback is responsible for executing the decrypted payload in memory.
Then three passes over the body – ^= xor1, bitwise NOT, ^= xor2 followed by a DWORD level Fisher–Yates de-shuffle and finally RC4 with the 16-byte key applied.
Dynamic API Resolution ✔ DInvokeCore class for dynamic API resolution T1027.007 ✘ Not implemented
The last 26 bytes of the file are a parameter block... three passes over the body – xor, bitwise NOT, xor – followed by a DWORD level Fisher–Yates de-shuffle and finally RC4.
Every section has been deliberately named to suggest it contains something else entirely... the section named .pdata is the import table.
Install directory %APPDATA%\Microsoft\Crypto\RuntimeBroker\... Masquerade RuntimeBroker.exe (impersonates Windows Runtime Broker).
“This technique can strip the internet-origin mark from the files inside, reducing the warnings Windows would normally display.”
Check Constant Fails if CPU cores <= 1... Physical RAM... Free disk... Uptime... Cursor moved... Screen resolution... Last user input.
Check Constant Fails if CPU cores <= 1... Physical RAM... Free disk... Cursor moved... Screen resolution... Last user input.
Process discovery ✔ This the capability to obtain a listing of running processes T1057 ✘ Not implemented
Check Constant Fails if CPU cores <= 1... Physical RAM... Free disk... Uptime... Cursor moved... Screen resolution... Last user input.
173 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
74 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET remote-access trojan delivered through DLL sideloading of a signed, renamed Notepad++ executable. It provides remote command execution, hidden VNC, data theft, and file-grabbing capabilities, with a configured C2 server at 154.36.188.201:4449.
VenomRAT v6.0.3 is the final payload in the PAPERMILL tax-themed phishing campaign, which appears focused on recipients in India. A disk-image attachment contains a renamed, legitimately signed Notepad++ executable that sideloads a malicious DLL. The loader decrypts an accompanying payload and uses Donut to execute the .NET RAT in memory. VenomRAT provides remote command access, hidden VNC, data theft and file grabbing, creating risks of surveillance, account theft and follow-on intrusion. Its recovered command-and-control endpoint is 154.36.188.201:4449. Researchers noted similarities to Silver Fox tradecraft but explicitly stopped short of attributing the campaign to that group.
A .NET remote-access trojan deployed as the final payload. This v6.0.3 build communicates with 154.36.188.201:4449 and includes RAT, hidden virtual network computing (HVNC), credential/data-stealing, and grabber capabilities. Its configuration includes a mutex and can support process-critical anti-kill behavior, although the anti-kill option is disabled in this sample.
A .NET remote-access trojan delivered as the final payload. This build supports remote command-and-control, HVNC, credential/data stealing, and grabbing capabilities; it includes D/Invoke-based hooked-API bypass functionality and can optionally make its process critical. The preceding loader handles elevation, persistence, and anti-analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.