Last seven days
- First activity
- Sep 9, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
GravityRAT is a closed-source remote access trojan and spyware family associated with long-running espionage activity primarily targeting Indian individuals and organizations, including defense, government, police, and related technology sectors.
Profile source: Mallory opens in a new tabGravityRAT
GravityRAT is a closed-source remote access trojan and spyware family associated with long-running espionage activity primarily targeting Indian individuals and organizations, including defense, government, police, and related technology sectors. Reporting has linked its operations to Pakistan-aligned threat activity, including clusters tracked as Cosmic Leopard and SpaceCobra, though some broader actor relationships remain unconfirmed. The malware has evolved from early Windows-focused intrusions into a multi-platform family with Windows and Android variants, and reporting also notes macOS-related variants within the broader campaign ecosystem.
On Windows, GravityRAT functions as a RAT with host reconnaissance, surveillance, and file-theft capabilities. Documented behavior includes enumerating running processes and services, collecting user-account details such as username and account metadata, gathering network configuration information including IP address, MAC address, and domain context, querying system date and time, and collecting processor information through WMI. It steals documents matching predefined extension lists and can monitor for removable media, collecting targeted files when USB storage is connected. Persistence has been observed through scheduled tasks configured to relaunch the malware regularly. Earlier delivery chains used malicious Microsoft Office documents, likely distributed by email, that downloaded the payload when macros were enabled. GravityRAT has also been noted for extensive anti-analysis and anti-virtualization checks.
On Android, GravityRAT has been distributed through trojanized applications, especially messaging and utility-themed apps, including highly targeted campaigns involving fake or gated chat platforms. Android variants have been observed collecting device identifiers, phone and SIM information, SMS messages, contacts, call logs, location-related data, build information, and files from device and external storage, including encrypted WhatsApp backup files in newer versions. Some Android variants stage stolen data locally before exfiltration and can receive commands to delete files, contacts, and call logs, indicating both surveillance and cleanup capabilities. Campaigns have relied on social engineering, spearphishing, malicious websites, and fake installers or trojanized apps to reach victims.
GravityRAT has been used as part of broader intrusion ecosystems alongside supporting loaders and administration tooling, enabling operators to manage infections across multiple concurrent campaigns. Its combination of targeted delivery, persistence, reconnaissance, surveillance, and document theft makes it a notable espionage malware family focused on long-term access and intelligence collection.
C2 tracking
Derp observations, rolling seven-day window
Samples
325fcec2985aca268d0ff98ffa1c2bf7055bd28b3f11501fe5b135de35ab28d5 455c2ae92b232457b9ca10189925086ce56a9d8db87f48f2395151399657e0ad 9dde922f2499576754b7eadaaf484ed1325dec5e5b78da1739a7bbfed9ac5ea1 ab1aec9324902074a735544d3513ac192bdf296a06724422cacf6bd0346b82e9 ba5e0e68207aee115f02fdfdba92155fd2cab6ca1d5cbe4fcc7e30904ca3d5e8 1e215abaa5b2aebee8304a75ec9c35c47fa07a5c42192857264c37ca16fe6f10 37f40128a3c7dc1826d5c0dc510d1e9cdcc448d68cba35b777733e4420aeddae 498eb23f2d3861e8cb9899bb7afa8aff5599a8aabae4f23877366e02d0fff997 618b4d0caf003bee22faff1739b60ed252360a7cb39449b8c1de6d27531ab7a5 7ab738452e05aa93c7dadbbaa6e14a94ed6ff2ebfc34af1d72bab7399c1d4c6e Reported operators
ESET researchers have identified an updated version of Android GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico.
GravityRAT, a closed-source malware family, first disclosed by Talos in 2018, is a Windows- and Android-based RAT used to target Indian entities.
MITRE ATT&CK
Reporting
ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.
Cisco Talos reported that GravityRAT, a remote access trojan used in targeted attacks against organizations in India, evolved over a two-year period into a more capable and evasive threat. The malware was delivered through malicious Microsoft Office documents, likely sent by email, and fetched its payload when victims opened the file and enabled macros. Researchers linked the campaign to persistent targeting activity and described the malware as an advanced RAT designed to maintain access to compromised systems. Analysis highlighted GravityRAT’s unusually extensive anti-analysis features, including seven virtual-machine detection techniques and a novel check of CPU temperature to identify hypervisor-based sandbox environments. The reporting also indicated the operators may have uploaded early lure documents to VirusTotal to measure static antivirus detection before wider use, underscoring a deliberate effort to refine delivery and evade security tools.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.