Revenge RAT

MITRE ATT&CK: S0379 View on attack.mitre.org

Aliases: Revetrat, Revenge RAT

First seen
2016-10-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
463 (424 malicious)
Last IoC activity
2026-09-02 00:37:52
Profile updated
2026-07-07 13:12:42

Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

Revenge RAT is a freely available remote access tool written in .NET (C#).

Recent IoC activity

425 malicious indicators in Maltiverse are attributed to Revenge RAT (S0379). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname kilimanjaro.theworkpc.com 2026-09-03 1
hostname rampage.myvnc.com 2026-09-03 1
hostname th8q3wj9w.localto.net 2026-09-02 1
hostname burkinafaso.duckdns.org 2026-09-02 1
hostname r3dc0d3r.duckdns.org 2026-09-02 1
file sample 2026-09-01_981037e1cb5b845ca3cd440b5181292e_agent-tesla_amadey_darkgate_elex_... 2026-09-02 1
hostname kilimanjaro.crabdance.com 2026-09-02 1
hostname kilimanjaro.hopto.org 2026-09-02 1
hostname alien007.my-firewall.org 2026-09-02 1
hostname kilimanjaro.run.place 2026-09-02 1
file sample 2026-08-30_10faf54e730929a1303727bb16abfc18_agent-tesla_amadey_darkgate_elex_... 2026-09-01 1
file sample 2026-08-30_727e453ed680723181026685a44edfc0_agent-tesla_amadey_darkgate_elex_... 2026-08-31 1
file sample 2026-08-30_81ff7b878b3cf1a0832b951137b6fafa_agent-tesla_amadey_darkgate_elex_... 2026-08-31 1
file sample _efffbda36edcb7d4130f65a57d3966e7694172fb5db37ce48f27849d239066c7.exe 2026-08-27 2
file sample 2026-08-25_ef036ecc52261d015efa2e8f764c3f73_agent-tesla_darkgate_elex_maze_remcos 2026-08-26 1
file sample 2026-08-25_fd2f536e6389666eb6eae854c76971ab_agent-tesla_darkgate_elex_maze_remcos 2026-08-26 1
file sample 2026-08-24_020f1823a942bbfe80d8003ba434ee91_agent-tesla_darkgate_elex_maze_remcos 2026-08-25 1
file sample 2026-08-24_04e7d64bb6822c367a769457f60e066b_agent-tesla_darkgate_elex_maze_remcos 2026-08-25 1
file sample 2026-08-24_24c898af6a3e9e0de4e03bf7834faca1_agent-tesla_darkgate_elex_maze_remcos 2026-08-25 1
file sample 60c30150ed574e2afb00acf25819d85bba6e2f646f6a785ef2ffe4326bc52e5d 2026-08-25 2

Detection coverage

  • 499 Sigma rules

Malware & tools used

  • Keylogging (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • OS Credential Dumping (attack-pattern)
  • Video Capture (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Mshta (attack-pattern)
  • Winlogon Helper DLL (attack-pattern)
  • Audio Capture (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • PowerShell (attack-pattern)
  • Indirect Command Execution (attack-pattern)
  • Screen Capture (attack-pattern)
  • Scheduled Task (attack-pattern)
  • System Owner/User Discovery (attack-pattern)

Used by threat actors

Reports & references

  • Kaspersky — 95229 (report)
  • Kaspersky — 114990 (report)
  • cylance.com — Whitecompanyoperationshaheenreport (report)
  • researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
  • github.com — Microsoft 365 Defender Hunting Queries (report)
  • blog.morphisec.com — Revealing The Snip3 Crypter A Highly Evasive Rat Loader (report)
  • proofpoint.com — Reservations Requested Ta558 Targets Hospitality And Travel (report)
  • blog.morphisec.com — Ahk Rat Loader Leveraged In Unique Delivery Campaigns (report)
  • blog.360totalsecurity.com — Bayworld Event Cyber Attack Against Foreign Trade Industry (report)
  • blog.yoroi.company — Aggah How To Run A Botnet Without Renting A Server For More Than A Year (report)
  • blog.reversinglabs.com — Rats In The Library (report)
  • blogs.360.cn — Apt C 44 (report)
  • mp.weixin.qq.com — Gwoirnplvqx761Lw8X S5G (report)
  • binarydefense.com — Revenge Is A Dish Best Served Obfuscated (report)
  • Cisco Talos — A Year Of Fajan Evolution And Bloomberg (report)
  • threatrecon.nshc.net — Sectorh01 Continues Abusing Web Services (report)
  • Cisco Talos — Rat Ratatouille Revrat Orcus (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Revenge Rat (report)
  • perception-point.io — Revenge Rat Back From Microsoft Excel Macros (report)
  • yoroi.company — The Evolution Of Aggah From Roma225 To The Rg Campaign (report)
  • isc.sans.edu — 22590 (report)
  • uptycs.com — Revenge Rat Targeting Users In South America (report)
  • blog.reversinglabs.com — Dotnet Loaders (report)
  • github.com — Revengerat.Md (report)
  • embee-research.ghost.io — Introduction To Dotnet Configuration Extraction Revengerat (report)

External references