Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:57:17 UTC Home > List all groups > List all tools > List all groups using tool VBREVSHELL Tool: VBREVSHELL Names VBREVSHELL Category Malware Type Backdoor Description (Mandiant) VBREVSHELL is a VBA macro that spawns a reverse shell relying exclusively on Windows API calls. Information Malpedia Last change to this tool card: 22 June 2023 Download this tool card in JSON format All groups using tool VBREVSHELL Changed Name Country Observed APT groups   APT 42 2015-Feb 2024   1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a9009c1b-7b90-4f76-8fba-1bc05f1879b2 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a9009c1b-7b90-4f76-8fba-1bc05f1879b2 Page 1 of 1