Netskope Threat Labs

OrcusRAT

ATP Sandbox Adv. HeuristicsAV

OrcusRAT (a.k.a. Orcus) is a remote administration tool advertised since early 2016 with a full command set for remote control. Its distinctive features are support for custom plugins drawn from a repository and the ability to execute C sharp and VB.NET code on remote machines in real-time. Because vendors sell the tool openly, defenders should triage its detections against authorized administrative tooling.

First seen
July 2023
Last seen
September 2026
OrcusRatOrcusrat
Alert Name
ByteCode-MSIL.Backdoor.OrcusRAT
ByteCode-MSIL.Trojan.Orcusrat
ByteCode-MSIL.Trojan.OrcusRat
ByteCode-MSIL.Trojan.OrcusRAT
Document-Word.Trojan.Orcusrat
Dropped:Generic.OrcusRAT.A.F9D3ABDD
Dump:Generic.OrcusRAT.A.420113F1
Dump:Generic.OrcusRAT.A.DBB3A19E
Generic.OrcusRAT.A.017491A5
Generic.OrcusRAT.A.01DD1892