Revenge RAT is a .NET-based Windows remote access trojan that has been active since at least 2016 and is commonly used in commodity cybercrime operations. It provides operators with interactive remote control and host surveillance functions, including screen capture, keylogging, collection of host identifiers such as username, IP address, and MAC address, and broader system reconnaissance such as installed security product enumeration. Reported samples also generate unique victim identifiers from host attributes and communicate collected data to command-and-control infrastructure, sometimes using Base64-encoded data in transit.
The malware is associated with multi-stage, script-driven infection chains that rely heavily on native Windows scripting and proxy execution mechanisms. Observed delivery and execution patterns include malicious documents, phishing lures, remote template injection, VBA macros, VBScript, PowerShell, and mshta-based script execution. Some campaigns used fileless or memory-resident stages, including PowerShell Reflection-based loading, while others used process hollowing into legitimate Windows binaries to evade detection. Revenge RAT has also been observed as a reconnaissance-stage component in broader malware chains that later deploy additional payloads.
Persistence mechanisms reported for Revenge RAT include scheduled tasks and Windows Registry autostart modification, including Winlogon Shell abuse. The malware has been linked to campaigns targeting hospitality, travel, and related organizations in Latin America, particularly Brazil, and has been repeatedly used by the financially motivated threat actor TA558 in reservation-themed phishing operations. It has also appeared alongside other commodity RATs such as Loda, AsyncRAT, njRAT, and Orcus-related delivery stages. Overall, Revenge RAT is best characterized as a commodity Windows RAT focused on surveillance, host profiling, persistence, and stealthy execution through script-based loaders and in-memory techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These early campaigns typically used malicious Word attachments that exploited Equation Editor vulnerabilities (e.g. CVE-2017-11882) or remote template URLs to download and install malware. | Two of the most common malware payloads included Loda and Revenge RAT.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bahamut utilized the publicly available, cross-platform remote administration tools (RATs) NETWIRE and Revenge RAT for remote control.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The actor sends malicious emails written in Portuguese, Spanish, and sometimes English. The emails use reservation-themed lures with business-relevant themes such as hotel room bookings.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
the downloaded file is a VBS file... We see that the malware dropped a Powershell script
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
In 2020, TA558 stopped using Equation Editor exploits and began distributing malicious Office documents with macros, typically VBA macros, to download and install malware. | The VBS script in turn downloaded and executed Revenge RAT.
These early campaigns typically used malicious Word attachments that exploited Equation Editor vulnerabilities (e.g. CVE-2017-11882)... In 2021, this actor continued to leverage emails with Office documents containing macros or Office exploits (e.g. CVE-2017-8570).
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content includes HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell, and notes Revenge RAT creates a Registry key at HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell to survive a system reboot.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Revenge RAT fileless components that execute reconnaissance and hollowing attacks on legitimate Windows processes to avoid being detected... executes a known process hollowing technique on a legitimate Windows process (RegAsm.exe).
his purpose is to RunPE (AKA process hollowing) the RAT inside the legit InstallUtil.exe Binary
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content includes HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell, and notes Revenge RAT creates a Registry key at HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell to survive a system reboot.
“Opera.ps1” is a highly obfuscated PowerShell script... After de-obfuscating the PowerShell code, we were able to retrieve the Windows executable, which is the Revenge RAT.
Revenge RAT fileless components that execute reconnaissance and hollowing attacks on legitimate Windows processes to avoid being detected... executes a known process hollowing technique on a legitimate Windows process (RegAsm.exe).
his purpose is to RunPE (AKA process hollowing) the RAT inside the legit InstallUtil.exe Binary
APT29 has use mshta to execute malicious scripts on a compromised host... APT32 has used mshta.exe for code execution... APT38 has used a renamed version of mshta.exe to execute malicious HTML files... FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.
GetActiveWindow : Get active window or window of the application used by the user
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
We see that this is the "Revenge RAT". C2: h0pe1759.ddns.net
230 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
63 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan referenced as the payload used in older instances of the same campaign before the actor shifted to AZORult and NanoCore in newer samples.
Revenge RAT is a remote access trojan used by the RevengeHotels group to gain unauthorized access to hotel and travel industry systems, often delivered via malicious documents exploiting Microsoft Office vulnerabilities.
A RAT component used filelessly in this campaign for reconnaissance, collecting host information and helping execute subsequent stages while using hollowing against legitimate Windows processes to evade detection.
Revenge RAT is a remote access trojan used by C.A.S to gain remote control over infected systems, execute commands, collect information, and maintain persistence. It is used for file management, credential theft, and defense evasion, including disabling security tools and adding itself to Windows Defender exclusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.