Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
GravityRAT is a closed-source remote access trojan and spyware family associated with long-running espionage activity primarily targeting Indian individuals and organizations, including defense, government, police, and related technology sectors.
Profile source: Mallory opens in a new tabGravityRAT
GravityRAT is a closed-source remote access trojan and spyware family associated with long-running espionage activity primarily targeting Indian individuals and organizations, including defense, government, police, and related technology sectors. Reporting has linked its operations to Pakistan-aligned threat activity, including clusters tracked as Cosmic Leopard and SpaceCobra, though some broader actor relationships remain unconfirmed. The malware has evolved from early Windows-focused intrusions into a multi-platform family with Windows and Android variants, and reporting also notes macOS-related variants within the broader campaign ecosystem.
On Windows, GravityRAT functions as a RAT with host reconnaissance, surveillance, and file-theft capabilities. Documented behavior includes enumerating running processes and services, collecting user-account details such as username and account metadata, gathering network configuration information including IP address, MAC address, and domain context, querying system date and time, and collecting processor information through WMI. It steals documents matching predefined extension lists and can monitor for removable media, collecting targeted files when USB storage is connected. Persistence has been observed through scheduled tasks configured to relaunch the malware regularly. Earlier delivery chains used malicious Microsoft Office documents, likely distributed by email, that downloaded the payload when macros were enabled. GravityRAT has also been noted for extensive anti-analysis and anti-virtualization checks.
On Android, GravityRAT has been distributed through trojanized applications, especially messaging and utility-themed apps, including highly targeted campaigns involving fake or gated chat platforms. Android variants have been observed collecting device identifiers, phone and SIM information, SMS messages, contacts, call logs, location-related data, build information, and files from device and external storage, including encrypted WhatsApp backup files in newer versions. Some Android variants stage stolen data locally before exfiltration and can receive commands to delete files, contacts, and call logs, indicating both surveillance and cleanup capabilities. Campaigns have relied on social engineering, spearphishing, malicious websites, and fake installers or trojanized apps to reach victims.
GravityRAT has been used as part of broader intrusion ecosystems alongside supporting loaders and administration tooling, enabling operators to manage infections across multiple concurrent campaigns. Its combination of targeted delivery, persistence, reconnaissance, surveillance, and document theft makes it a notable espionage malware family focused on long-term access and intelligence collection.
C2 tracking
Derp observations, rolling seven-day window
Samples
006df099d07e89b3f9bfe40fc18dba589091f0a05e26891f90b9308373fbf2c7 338ce79713fd7f8cc9163cc6378a5b0a3b4c7f0f3a1fbb37fc2d60d91de833b8 5390f64168642a410feb739b0c00cdcbd4c48d95eb5fa8b0bca576b5eb9bd40f a41d87682d5ae51bb8f5fdc99906b93d047292b8073c20dba83aa3ce9fd42634 a7d5e247ef34343c2c54835321a0a8e4d889519e68976b05ee42d38bfbba1409 Reported operators
ESET researchers have identified an updated version of Android GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico.
GravityRAT, a closed-source malware family, first disclosed by Talos in 2018, is a Windows- and Android-based RAT used to target Indian entities.
MITRE ATT&CK
Reporting
ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.
Cisco Talos reported that GravityRAT, a remote access trojan used in targeted attacks against organizations in India, evolved over a two-year period into a more capable and evasive threat. The malware was delivered through malicious Microsoft Office documents, likely sent by email, and fetched its payload when victims opened the file and enabled macros. Researchers linked the campaign to persistent targeting activity and described the malware as an advanced RAT designed to maintain access to compromised systems. Analysis highlighted GravityRAT’s unusually extensive anti-analysis features, including seven virtual-machine detection techniques and a novel check of CPU temperature to identify hypervisor-based sandbox environments. The reporting also indicated the operators may have uploaded early lure documents to VirusTotal to measure static antivirus detection before wider use, underscoring a deliberate effort to refine delivery and evade security tools.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.