Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
104
Global rank
81 infographic chevron month
Month rank
56 infographic chevron week
Week rank
0
IOCs

Revenge was one of the most popular remote access trojans to be used in 2019 when it was featured in a huge malicious campaign named “Aggah”. This malware can take remote control of infected machines and spy after the victims.

Trojan
Type
Unknown
Origin
1 January, 2016
First seen
27 August, 2026
Last seen

How to analyze Revenge with ANY.RUN

Type
Unknown
Origin
1 January, 2016
First seen
27 August, 2026
Last seen

IOCs

IP addresses
23.52.181.141
20.190.157.0
74.179.77.204
57.155.104.224
172.211.123.250
48.192.1.65
48.209.138.168
57.153.246.3
2.16.164.73
74.179.77.164
23.52.181.212
139.99.85.213
2.59.254.111
154.91.34.165
176.65.144.23
208.95.112.1
45.141.233.69
185.156.72.2
188.114.96.3
75.119.193.253
Hashes
172219ebfb21af389340f25b529f74979f57a498cedd7b2fc3d190b4645b3eb3
677e21051a3bed2d212ecd9c312a7c2ebf6a9c02c55533479e207f3a90cb5048
fc9983cc6571001525859be91c1d188365d5755de010cb90f9f48e0c690ee40a
74d955f8200fc650be9239176da0f774e2e6d01265ed5920a25c06e0df7c092f
21c8bc09b4957fb82a4f09fc4924be84f00d9fc1e253e89c102edf5d4773ee80
54d8c9cfdfaa4def013260dd34f6da0120ffe1f1f58f32b2904502a9deee228b
593b017739f33d55f96be520130dadfe13d013a53d446ba919d346eaa7b84b9b
7e32bf2a01166d4b04bddb5d09d6d7df5278d19b9a08948b3f7d2c728f0d1f5b
d848c68fcaf806872cadc3af024140a4e02df228d6b55b82e46ba93764ff36be
27f12cd77567c12a0f81639231bcd18f2dfae182ba74b77babcdf443642782c5
d0fa9915b0c7069b59241e797933af7d2a6f50b110b61f012bbb2c8915bf563a
da687ee2cd0c9c515119af4365a97683a4267454d76f239f61273707afc6aeae
c5d707f6d23b0ac6076d7f3269d814fc1a457e413e6ececd355cab2a09a57242
cdc9308aece1c494a2d287aa240f6f816a4a3bcf9dc892e09d7ea0784bae46be
484f394a623ccbbb5e1000024ec4deb71d5328371d3470a334dc598ce0952523
2f49a710c62575e6e830ca8a52b64de12a6cabc5b9b6715626224a7fb06b757e
9b9b93b6ca53c5c27063a9939d93f6c9f1431391c86264cc2f283b87f8e0d2d8
7cdc8d5a6ac74591a35852e3ba1b9b4432cb7c15cea2eaf73afa7b54a8f75341
b157a31e49fcccdddff93dd687e245c1a8c96e209989e7bbc65f6162dc083297
72d47ae3e64e706de6eb1a92de29714c363cc1b85b68c4e5aecd2b72825d3f7a
Domains
www.microsoft.com
activation-v2.sls.microsoft.com
fe3cr.delivery.mp.microsoft.com
login.live.com
slscr.update.microsoft.com
go.microsoft.com
client.wns.windows.com
google.com
settings-win.data.microsoft.com
crl.microsoft.com
reallyfreegeoip.org
www.dontlookhere.com
s3.timeweb.cloud
mail.dhakahome.com
ip-api.com
gstatic.com
api.pcloud.com
dontlookhere.com
api.telegram.org
checkip.dyndns.org
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.2.crl
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.1.crl
https://gstatic.com/generate_204
https://api.pcloud.com/listfolder?path=/
http://ip-api.com/json/
https://cloud-api.yandex.net/v1/disk/resources?path=/&limit=500
http://ip-api.com/line/?fields=hosting
http://checkip.dyndns.org/
https://reallyfreegeoip.org/xml/212.30.36.20
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2800
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7890
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10855
comments 0

What is Revenge Malware?

Revenge belongs to the class of Remote Access Trojans which means that it is usually used by the attackers to control infected PCs remotely or spy on the users by monitoring keystrokes and even computer surroundings through the remote webcam and microphone access.

Discovered for the first time in 2016, Revenge RAT continues to be a threat at the present day with a big spike in popularity monitored in 2019, when the malware was observed targeting corporations and government structures all around the world in a massive malicious campaign codenamed “Aggah”. Thanks to a large variety of distribution methods similar to ransomware, robust core feature-set, and solid persistence mechanisms, Revenge has become a popular choice for cybercriminals. The popularity of this RAT was further aided by its open-source nature – anybody can freely download Revenge on underground hacking forums and employ it in their own campaigns.

General description of Revenge

The Revenge RAT was first observed in the wild in June 2016, when it was released by a user with a nick Napoleon – an Arabic-speaking member of the underground hacking community.

The initial version of this malware was a simple malicious program that didn’t offer much, if any, code obfuscation and was mainly used by other Arabic-speaking cybercriminals. Despite the simplicity of the malware, at the time, only one out of 54 of VirusTotal scanners could pick up the malicious nature of the Revenge code, which confused the researchers bearing in mind the lack of anti-analysis techniques.

The creator used Visual Basic to develop this RAT and personally admitted that the malware was very bare-bones at the time of its initial release– providing only the most basic functions and definitely losing to competitors in terms of core feature-set. According to Napoleon, this explained why Revenge was available free of charge.

After two months since the initial release, a new version v0.2 was issued by the author, on a more popular hacking forum, this time with more features, but still offered completely free of charge. Since then Revenge has evolved even further and today, it offers cybercriminals a wide range of capabilities including remote files and registry alterations on an infected machine, access to memory, processes, and services as well as access to connected devices such as keyboards, webcams, and mice, allowing this malware to record the actions of its victims and collect information like banking credentials and social account data.

Core malicious feature-set was not the only thing that evolved over the course of the Revenge lifetime. Improvements in distribution and persistence made this threat truly a force to be reckoned with. In some campaigns, scripts were executed in the HTML of a custom Blogspot [com] page.

Revenge malware analysis

A video recorded in the ANY.RUN malware hunting service allows us to take a look at the execution of this malware as it unfolds and also other malicious programs like ransomware.

process graph of the revenge trojan execution Figure 1: Displays the lifecycle of Revenge in a visual form. A graph generated by ANY.RUN

text report of the revenge analysis Figure 2: Shows a customizable text report generated by the ANY.RUN malware analysis service which allows diving deeper into the details of the Revenge execution process.

Revenge execution process

Sometimes the first steps of Revenge trojan execution may vary depending on how it made its way into a victim's computer. The most common form of initial infiltration vector is by the use of Mshta.exe for downloading the payload or for direct execution from a URL. After the payload is delivered to the infected machine, Mshta.exe changes the autorun value in the registry and starts three processes - cmd.exe, powershell.exe and schtasks.exe. It starts cmd.exe to kill processes from a list, in the given example processes from the Microsoft Office packet were targeted. Powershell.exe is being launched to download the main payload. In turn, schtasks.exe is launched in a way to generate a scheduled task that provides Revenge persistence in the infected system. After all these steps, the malware is ready to complete commands from C2 servers.

How to avoid infection by Revenge?

The best line of defense against threats like Revenge RAT is to keep a security product installed and updated with the latest firmware. One should not disable native Windows security features, regularly update the OS and adhere to the best security practices of staying safe online.

As such, it is advised to stay clear of downloading email attachments from unknown senders and never enabling macros in Microsoft Office if prompted to do so by a file downloaded from a suspicious email. The same advice comes for other threats like Glupteba and Smoke Loader.

Distribution of Revenge

Revenge has been seen being distributed in a variety of ways the same as ransomware, some of which are potentially more effective than others. For example, Revenge is known to infect PCs from malicious email attachments and corrupted ads on compromised websites.

Most commonly, once delivered in the Microsoft Office file that was downloaded and launched by the potential victim, Revenge will use macros to connect to an outside domain, sometimes hidden on a web page, from which additional scripts and content are downloaded until the actual malware is installed on the PC.

How to detect Revenge RAT using ANY.RUN?

Analysts can get information about which MITRE ATT&CK™ MATRIX techniques were applied by malware. Just click on the "ATT&CK™ MATRIX " button.

Revenge MITRE ATT&CK MATRIX techniques Figure 3: Revenge MITRE ATT&CK MATRIX techniques

Conclusion

Revenge is no slouch when it comes to Remote Banking Trojans. It has begun its lifespan as a simplistic malware such as ransomware and without anti-analysis features but has evolved to become a capable and persistent trojan used in massive attacks in Europe, North America, Asia, and the Middle East.

The popularity of this malware is not only due to its robust feature-set, but also ready availability since Revenge can be downloaded for free from a number of underground communities.

Professionals can establish a secure cyber defense against Revenge and similar RATs and secure their corporate or government networks by reverse engineering and studying a threat using malware hunting services like to ANY.RUN.

HAVE A LOOK AT

JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
Latrodectus screenshot
Latrodectus
latrodectus
Latrodectus is a malicious loader that is used by threat actors to gain a foothold on compromised devices and deploy additional malware. It has been associated with the IcedID trojan and has been used by APT groups in targeted attacks. The malware can gather system information, launch executables, and detect sandbox environments. It uses encryption and obfuscation to evade detection and can establish persistence on the infected device.
Read More
MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
Spynote screenshot
Spynote
spynote
SpyNote, also known as SpyMax and CypherRat, is a powerful Android malware family designed primarily for surveillance and data theft, often categorized as a Remote Access Trojan (RAT). Originally emerged in 2016, SpyNote has evolved significantly, with new variants continuing to appear as recently as 2023–2025.
Read More
FlowerStorm screenshot
FlowerStorm
flowerstorm
FlowerStorm is a phishing-as-a-service (PhaaS) platform used by cybercriminals to steal Microsoft 365 credentials and bypass multi-factor authentication (MFA) protections through adversary-in-the-middle (AiTM) attacks. Emerging after the disruption of Rockstar2FA in late 2024, FlowerStorm rapidly gained popularity among attackers targeting enterprises across North America and Europe.
Read More
SVCStealer screenshot
SVCStealer
svcstealer
SVCStealer is an information-stealing malware targeting sensitive user data through spear-phishing email attachments. It systematically extracts credentials, financial data, and system information from various applications, including browsers and messaging platforms.
Read More