Netskope Threat Labs

VenomRAT

ATP Sandbox Adv. HeuristicsAVNetskope IPS

VenomRAT is a .NET based remote access trojan that gives cyberattackers extensive control over infected systems, including remote shell, file management, and keystroke logging. Its open source builder and plugin modules made it popular with low skilled operators, and modified editions circulate widely in phishing campaigns. Its interface and feature set descend from other open source RAT families, and detections should trigger credential resets and full implant removal.

First seen
June 2024
Last seen
October 2026
VenomRatVenomrat
Alert Name
ByteCode-MSIL.Backdoor.VenomRat
ByteCode-MSIL.Backdoor.VenomRAT
ByteCode-MSIL.Trojan.VenomRAT
Document-HTML.Trojan.VenomRAT
Gen:Variant.Backdoor.Marte.VenomRAT.12
Gen:Variant.Backdoor.Marte.VenomRAT.13
Gen:Variant.Backdoor.Marte.VenomRAT.32
Gen:Variant.Backdoor.Marte.VenomRAT.34
Gen:Variant.Backdoor.Marte.VenomRAT.44
Gen:Variant.Backdoor.Marte.VenomRAT.45