ATT&CKSoftwareRevenge RAT

Revenge RAT

S0379

Malware.View on attack.mitre.org

About this malware

Revenge RAT is a freely available remote access tool written in .NET (C#).

Techniques used18

Procedure examples18

TechniqueProcedure example
T1003
OS Credential Dumping

Revenge RAT has a plugin for credential harvesting.

T1016
System Network Configuration Discovery

Revenge RAT collects the IP address and MAC address from the system.

T1021.001
Remote Desktop Protocol

Revenge RAT has a plugin to perform RDP access.

T1033
System Owner/User Discovery

Revenge RAT gathers the username from the system.

T1053.005
Scheduled Task

Revenge RAT schedules tasks to run malicious scripts at different intervals.

T1056.001
Keylogging

Revenge RAT has a plugin for keylogging.

T1059.001
PowerShell

Revenge RAT uses the PowerShell command Reflection.Assembly to load itself into memory to aid in execution.

T1059.003
Windows Command Shell

Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine.

T1082
System Information Discovery

Revenge RAT collects the CPU information, OS information, and system language.

T1102.002
Bidirectional Communication

Revenge RAT used blogpost.com as its primary command and control server during a campaign.

T1105
Ingress Tool Transfer

Revenge RAT has the ability to upload and download files.

T1113
Screen Capture

Revenge RAT has a plugin for screen capture.

T1123
Audio Capture

Revenge RAT has a plugin for microphone interception.

T1125
Video Capture

Revenge RAT has the ability to access the webcam.

T1132.001
Standard Encoding

Revenge RAT uses Base64 to encode information sent to the C2 server.

View all 18 procedure examples

Groups that use it2

Campaigns0

None recorded.

References2

  1. Cofense RevengeRAT Feb 2019 Open source
    Gannon, M. (2019, February 11). With Upgrades in Delivery and Support Infrastructure, Revenge RAT Malware is a Bigger Threat. Retrieved November 17, 2024.
  2. Cylance Shaheen Nov 2018 Open source
    Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.