{
  "family": "orcusrat",
  "sample_count": 1,
  "category": "ransomware",
  "description": "<h3>Executive Summary</h3>\nOrcus RAT is a highly sophisticated, commercially available Remote Access Trojan (RAT). It is controversially marketed and sold on surface-web forums as a legitimate \"Remote Administration Tool\" for system administrators. However, its expansive feature set, stealth capabilities, and use of custom plugins make it a favored weapon for cybercriminals conducting espionage and data theft.\n\n<h3>Technical Capabilities and Architecture</h3>\nOrcus RAT is built on a robust, modular architecture. It utilizes a client-server model where the attacker uses a dedicated administration panel to manage thousands of infected endpoints (clients). \n\nThe RAT provides attackers with granular, unfettered access to the compromised machine. Its core capabilities include:\n<ul>\n<li><strong>Live Surveillance:</strong> Real-time keylogging, remote desktop viewing (VNC-style access), and the ability to secretly activate webcams and microphones to monitor the victim's physical environment.</li>\n<li><strong>System Manipulation:</strong> A comprehensive file manager allowing for the stealthy upload, download, and execution of secondary payloads. It also includes registry editors and task managers to kill security software processes.</li>\n<li><strong>Plugin Extensibility:</strong> Orcus supports custom C# plugins, allowing threat actors to rapidly develop and deploy new capabilities, such as cryptocurrency stealers or specialized ransomware modules, tailored to specific campaigns.</li>\n</ul>\nOrcus RAT typically achieves persistence via scheduled tasks and registry run keys, and employs advanced obfuscation to evade static antivirus signatures.\n\n<h3>Threat Impact</h3>\nAn Orcus RAT infection constitutes a total loss of confidentiality, integrity, and availability on the affected host. It is frequently utilized in targeted corporate espionage, financial fraud, and as an initial access vector for ransomware syndicates.\n\n<h3>Detection and Eradication</h3>\n<ul>\n<li><strong>Behavioral Analytics:</strong> Deploy EDR solutions tuned to detect anomalous behaviors, such as unexpected processes hooking the keyboard (keylogging) or unauthorized applications accessing the webcam.</li>\n<li><strong>Network Monitoring:</strong> Inspect outbound network traffic for the distinct command-and-control (C2) communication patterns utilized by the Orcus server panel, often occurring over non-standard, encrypted ports.</li>\n<li><strong>System Rebuild:</strong> Due to the deep system hooks and the potential for secondary payload deployment, the most secure remediation strategy for an Orcus RAT infection is a complete wipe and re-image of the compromised endpoint.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "RAT.Orcus",
    "Trojan.OrcusRAT",
    "OrcusRemote"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1071.001",
    "T1056.001",
    "T1113",
    "T1125",
    "T1105"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:03:45Z",
  "type": "Remote Access Trojan",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}