Revenge RAT is a publicly available remote access trojan used to remotely control compromised systems. Its documented Windows capabilities include plugins for Remote Desktop Protocol access, credential harvesting, keylogging, and screen capture. It collects the current username and host network identifiers, including IP and MAC addresses, and uses Base64 encoding for information transmitted to its command-and-control server.
Revenge RAT can load itself into memory through PowerShell and .NET assembly reflection. It also abuses the Microsoft HTML Application host to execute malicious scripts and schedules scripts to run at recurring intervals. It establishes persistence across reboots through a per-user Winlogon shell registry modification. These behaviors combine remote access and surveillance with native Windows execution mechanisms and in-memory loading.
Revenge RAT has been used by Bahamut for remote control and by TA558 in campaigns targeting hospitality, hotel, travel, and related organizations, particularly Portuguese- and Spanish-speaking organizations in Latin America. TA558 has delivered it through reservation-themed phishing emails, malicious Office documents, remote template injection, and VBA macros. Documented infection chains include PowerPoint attachments that invoke PowerShell and retrieve an intermediate script before installing the trojan. TA558 has also delivered Revenge RAT through an invoice-themed Excel macro attachment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These early campaigns typically used malicious Word attachments that exploited Equation Editor vulnerabilities (e.g. CVE-2017-11882) or remote template URLs to download and install malware. | Two of the most common malware payloads included Loda and Revenge RAT.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bahamut utilized the publicly available, cross-platform remote administration tools (RATs) NETWIRE and Revenge RAT for remote control.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content includes HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell, and notes Revenge RAT creates a Registry key at HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell to survive a system reboot.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content includes HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell, and notes Revenge RAT creates a Registry key at HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell to survive a system reboot.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
230 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
66 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan referenced as the payload used in older instances of the same campaign before the actor shifted to AZORult and NanoCore in newer samples.
Revenge RAT is a remote access trojan used by the RevengeHotels group to gain unauthorized access to hotel and travel industry systems, often delivered via malicious documents exploiting Microsoft Office vulnerabilities.
A RAT component used filelessly in this campaign for reconnaissance, collecting host information and helping execute subsequent stages while using hollowing against legitimate Windows processes to evade detection.
Revenge RAT is a remote access trojan used by C.A.S to gain remote control over infected systems, execute commands, collect information, and maintain persistence. It is used for file management, credential theft, and defense evasion, including disabling security tools and adding itself to Windows Defender exclusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.