Skip to content

GravityRAT

GravityRAT is a closed-source remote access trojan and spyware family associated with long-running espionage activity primarily targeting Indian individuals and organizations, including defense, government, police, and related technology sectors.

Profile source: Mallory opens in a new tab

GravityRAT

Family profile

GravityRAT is a closed-source remote access trojan and spyware family associated with long-running espionage activity primarily targeting Indian individuals and organizations, including defense, government, police, and related technology sectors. Reporting has linked its operations to Pakistan-aligned threat activity, including clusters tracked as Cosmic Leopard and SpaceCobra, though some broader actor relationships remain unconfirmed. The malware has evolved from early Windows-focused intrusions into a multi-platform family with Windows and Android variants, and reporting also notes macOS-related variants within the broader campaign ecosystem.

On Windows, GravityRAT functions as a RAT with host reconnaissance, surveillance, and file-theft capabilities. Documented behavior includes enumerating running processes and services, collecting user-account details such as username and account metadata, gathering network configuration information including IP address, MAC address, and domain context, querying system date and time, and collecting processor information through WMI. It steals documents matching predefined extension lists and can monitor for removable media, collecting targeted files when USB storage is connected. Persistence has been observed through scheduled tasks configured to relaunch the malware regularly. Earlier delivery chains used malicious Microsoft Office documents, likely distributed by email, that downloaded the payload when macros were enabled. GravityRAT has also been noted for extensive anti-analysis and anti-virtualization checks.

On Android, GravityRAT has been distributed through trojanized applications, especially messaging and utility-themed apps, including highly targeted campaigns involving fake or gated chat platforms. Android variants have been observed collecting device identifiers, phone and SIM information, SMS messages, contacts, call logs, location-related data, build information, and files from device and external storage, including encrypted WhatsApp backup files in newer versions. Some Android variants stage stolen data locally before exfiltration and can receive commands to delete files, contacts, and call logs, indicating both surveillance and cleanup capabilities. Campaigns have relied on social engineering, spearphishing, malicious websites, and fake installers or trojanized apps to reach victims.

GravityRAT has been used as part of broader intrusion ecosystems alongside supporting loaders and administration tooling, enabling operators to manage infections across multiple concurrent campaigns. Its combination of targeted delivery, persistence, reconnaissance, surveillance, and document theft makes it a notable espionage malware family focused on long-term access and intelligence collection.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 2, 2026
Last activity
Sep 2, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
SpaceCobra

ESET researchers have identified an updated version of Android GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico.

Cosmic Leopard

GravityRAT, a closed-source malware family, first disclosed by Talos in 2018, is a Windows- and Android-based RAT used to target Indian entities.

MITRE ATT&CK

GravityRAT in ATT&CK

41 distinct techniques

Reporting

Research mentioning GravityRAT

Sep 2
Eset Welivesecurity

KryptoCibule: The multitasking multicurrency cryptostealer

ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.

Apr 27
Virusbulletin

Virus Bulletin :: GravityRAT malware takes your system's temperature

Cisco Talos reported that GravityRAT, a remote access trojan used in targeted attacks against organizations in India, evolved over a two-year period into a more capable and evasive threat. The malware was delivered through malicious Microsoft Office documents, likely sent by email, and fetched its payload when victims opened the file and enabled macros. Researchers linked the campaign to persistent targeting activity and described the malware as an advanced RAT designed to maintain access to compromised systems. Analysis highlighted GravityRAT’s unusually extensive anti-analysis features, including seven virtual-machine detection techniques and a novel check of CPU temperature to identify hypervisor-based sandbox environments. The reporting also indicated the operators may have uploaded early lure documents to VirusTotal to measure static antivirus detection before wider use, underscoring a deliberate effort to refine delivery and evade security tools.

Apr 26
Talos Intelligence

GravityRAT - The Two-Year Evolution Of An APT Targeting India

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.