Researchers documented WebMonitor, a commodity remote access trojan sold on underground forums by an actor known as Revcode, as part of a broader shift toward RAT-as-a-Service offerings that bundle malware with hosted command-and-control infrastructure. Instead of requiring buyers to stand up their own servers, WebMonitor provided browser-based administration panels and customer-specific virtual hosts under domains including revcode[.]eu and later wm01[.]to, lowering the barrier to entry for less-skilled operators. Palo Alto Networks said the malware had been marketed since 2017 and was linked to more than 2,000 infection attempts observed against customers across multiple industries worldwide.
The malware was described as being written in Visual Basic 6, packed with UPX, installed in the victim's AppData\Roaming directory, and configured for persistence through HKCU Run registry keys. Researchers also noted suspicious DNS behavior in later samples and a one-off connection to a Monero mining pool, suggesting the author may have been testing additional capabilities. Separate reporting on Quaverse RAT similarly highlighted the emergence of remote-access malware sold with service-based infrastructure, underscoring how hosted C2 panels and subscription-style support are turning commodity RAT operations into easier-to-deploy criminal services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
A Krebs on Security report cited Swedish business and tax records indicating that RevCode, the company behind WebMonitor, was owned by Alex Yücel, who had pleaded guilty in 2015 to creating and selling the Blackshades RAT. RevCode denied any connection to Blackshades and claimed the listed owner was not the same person.
Palo Alto Networks publicly documented WebMonitor as a previously undocumented commodity RAT with hosted C2 infrastructure, reporting more than 2,000 infection attempts and over 500 distinct samples observed.
Samples first observed in late November 2017 began performing DNS lookups for multiple non-existent domains in the form <username>.<8_char_hex_value>.to, indicating a change in behavior whose purpose was unclear.
A second root command-and-control domain, wm01[.]to, was brought online in late July 2017, expanding WebMonitor's centralized C2-as-a-service infrastructure beyond revcode[.]eu.
An actor using the name "Revcode" advertised WebMonitor on HackForums in May 2017, offering the malware as a commodity RAT with hosted web-based command-and-control.
The report says apparent testing activity for the WebMonitor RAT was first observed in late February 2017, marking the earliest known activity tied to the malware.
The report states WebMonitor had been on the market since at least mid-2017, sold in multiple editions for prices ranging from €14.99 to €29.99.
In January, a partner identified as "Softpatch" offered an Android RAT client related to WebMonitor and posted source code on GitHub.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourcetrustwave.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.