Unveiling RevC2 and Venom Loader
ID: ab37c77e-7f97-5480-94ba-09af2a1ac6de
STIX ID: report--ab37c77e-7f97-5480-94ba-09af2a1ac6de
Feed Name: Zscaler Security Research Blog
This report analyzes two malware campaigns: one using a VenomLNK/API documentation lure to deploy the RevC2 backdoor (WebSocket-based C2, JSON commands, capabilities including password/cookie theft, screenshots, shell execution, SOCKS5 proxying, and remote execution as other users) and a second using a cryptocurrency-transaction lure to deploy Venom Loader which loads the Retdoor JavaScript backdoor (encoded per-victim payloads using %computername%, persistence via autorun, HTTP POST polling for commands). The analysis provides command and data formats, sample C2 addresses and artifacts, and a Python emulation script for RevC2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
