RevengeRAT is a .NET-based remote access trojan that has been in circulation since at least 2016 and has been widely used by multiple unrelated threat actors after its source code became publicly available. It is commonly deployed as commodity malware in phishing-driven intrusion chains and provides attackers with remote control of compromised Windows systems together with information-theft functionality. Reported use spans criminal campaigns and broader malware distribution operations targeting organizations and individuals worldwide, including government, financial services, information technology, hospitality, tourism, education, energy, pharmaceuticals, transportation, and other sectors.
Observed delivery is primarily through phishing and malspam campaigns using lures such as complaints, invoices, reservations, quotations, and similar business-themed pretexts. Infection chains associated with RevengeRAT have used malicious Office documents, compressed archives, batch scripts, JavaScript, VBScript, PowerShell, and cloud- or paste-hosted staging content. Campaigns have also used obfuscation, steganographic payload retrieval, registry-stored payloads, and multi-stage loaders to hinder analysis and detection.
RevengeRAT functions as a full-featured RAT for post-compromise control and data theft. High-confidence reporting links it to remote administration of victim machines and theft of sensitive information, including credentials and keystrokes in some campaigns. It has also appeared alongside loaders and injectors that execute payloads in memory or through reflective loading, and it has been associated with persistence mechanisms such as Startup-folder execution and recurring script-based relaunch. Some campaigns using RevengeRAT have incorporated process injection, defense evasion, and layered command-and-control obfuscation.
The malware has been observed in operations attributed to or associated with actors such as TA558 and in campaigns documented by Cisco Talos and Morphisec, while other reporting notes possible but low-confidence links between certain RevengeRAT activity and operators of ObliqueRAT. Because leaked-source RATs are frequently modified, infrastructure overlap or code similarity alone is not sufficient for strong attribution. RevengeRAT remains best understood as a broadly reused commodity Windows RAT that is easy for adversaries to customize and embed in diverse phishing-led attack chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.
Aggah specifically has been seen using paste.ee to host njRAT, NetWire RAT, RevengeRAT, Agent Tesla.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
In general, the emails in every case claim to be associated with complaints against the organization being targeted. They purport to be from various authorities such as the Better Business Bureau (BBB).
When executing the LNK file, the Batch script starts to perform several Powershell commands.
The attached ZIP archives contain malicious batch files responsible for retrieving the malicious PE32 file and executing it... Later versions of the .bat downloader featured the use of obfuscation...
This sample uses largely the same structure as before, but uses randomized namespace and type names. This breaks our original script as there is no Nuclear_Explosion namespace or Atomic class to signature from.
There are two large arrays that contain: Compressed bytes of AgentTesla; Compressed bytes of a .NET Injector used for process injection... responsible for injecting AgentTesla payload into an instance of “aspnet_compiler.exe”.
They pointed the DDNS over to the Portmap service to provide an additional layer of infrastructure obfuscation. Portmap is a service designed to facilitate external connectivity to systems that are behind firewalls or otherwise not directly exposed to the internet.
This script deobfuscates a PowerShell command that downloads the next stage from a Pastebin-like sharing platform service called stikked.ch.
119 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan listed as one of the malware families deployed by TA558 for remote control and information theft.
Remote access trojan capability referenced as a likely final-stage RAT payload delivered by the campaign, enabling full command-and-control and data theft and potential lateral movement.
A remote access trojan used as a final payload in the PowerShell loader chain.
A .NET remote access trojan used here as the primary sample to demonstrate configuration extraction from IL instructions and ldstr-loaded strings, including across obfuscated variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.