Venom RAT is a commercially distributed remote access trojan targeting Windows systems. It supports remote command execution, file management, keylogging, surveillance, data exfiltration, and reverse-proxy functionality. A premium hidden VNC (hVNC) feature enables operators to interact with compromised systems through desktops that are invisible to the victim. Cracked versions have also circulated in cybercriminal communities.
Venom RAT has been delivered through phishing emails using invoice, hotel-reservation, and job-application lures, with multistage JavaScript and PowerShell delivery chains. Kiss Loader has deployed it through phishing-delivered shortcuts and WebDAV-hosted resources, decrypting and executing the final payload through asynchronous procedure call injection. Venom RAT also supports propagation through removable USB drives.
Its persistence and defense-evasion features include Windows Registry modifications, process discretionary access control list changes, anti-termination protection, and termination of security-related processes. When already running with elevated privileges, it can enable debug privileges and mark itself as a critical system process. It can interfere with Microsoft Defender Antivirus and modify scheduled-task and Registry settings to disable security software.
Venom RAT has been used by multiple unrelated threat actors. OPERA1ER added it to its arsenal in 2021 during activity primarily targeting African banking and financial-services organizations. UAC-0050 used it in campaigns affecting Ukraine, while TA558-associated RevengeHotels activity deployed it against hotels in Brazil and Spanish-speaking markets to support theft of payment-card data. Infrastructure associated with Venom RAT was disrupted during the multinational Operation Endgame action in November 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“In 2021 OPERA1ER changed arsenal RATs to: Neutrino, BlackNET, bitrat and 888_rat, Venom RAT.”
...застосовано... шкідливих програм: REMCOS RAT, QUASAR RAT, VENOM RAT, REMOTE UTILITIES та LUMMASTEALER.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
"...для проникнення до мережі зловмисники використовували скомпрометовані облікові записи VPN..."
Across these threads, the same pattern continued: promotion of RATs, crypters, and related tooling... On DarkForums itself, the same user was found promoting a range of tools, including... APK encryption and bypass methods... This thread, posted by “markoliver,” promoted an APK encryption method...
Le logiciel malveillant est principalement distribué par le biais de courriels de spear-phishing contenant des pièces jointes ou des liens malveillants, souvent en usurpant l'identité d'entités légitimes.
hVNC utilizes the Microsoft Windows Desktop API to craft a hidden desktop via the Windows feature CreateDesktop. This concealed desktop remains invisible to users... hVNC capabilities go beyond mere observation, actively emulating keyboard and mouse input, allowing cybercriminals to navigate compromised systems with precision.
195 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AsyncRAT Family Threat Overview AsyncRAT BitRAT DCRat Quasar RAT Venom RAT
Remote access trojan promoted in a Pro HVNC RAT variant.
A remote access trojan observed on the same /24 subnet among other criminal tooling.
Remote access trojan delivered as the final payload by Kiss Loader; described as an AsyncRAT variant and executed via APC injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.