Skip to content

ReverseRAT

ReverseRAT is a custom C# remote access trojan used by the Pakistan-linked SideCopy (TAG-140) threat cluster since at least early 2021.

Profile source: Mallory opens in a new tab

ReverseRAT

Family profile

ReverseRAT is a custom C# remote access trojan used by the Pakistan-linked SideCopy (TAG-140) threat cluster since at least early 2021. It has been deployed against Indian government, defense, critical-infrastructure, and academic targets, commonly through spear-phishing campaigns using weaponized archives, deceptive Windows shortcut lures, and HTML Application stages executed through mshta.exe. ReverseRAT supports host and installed-software discovery, screenshot capture, password and clipboard theft, file manipulation, command execution, file upload, and interactive shell access. It can establish Registry-based persistence and uses encrypted command-and-control communications. Observed infection chains employ staged payload delivery, reflective DLL loading, in-memory reconstruction and execution, obfuscation, and artifact deletion to hinder file-based detection. ReverseRAT also supports downloading and executing additional payloads, self-updating, and self-termination.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance

Observed infrastructure

Last seven days

First activity
Sep 22, 2026
Last activity
Sep 22, 2026
Feed role
C2 / Distribution
Host form
0 IP / 2 hostnames

Reported operators

Threat actors

2 named in public reporting
SideCopy

DLL-датотеката е Remote Access Trojan (RAT) наречен ReverseRAT, кој SideCopy го користи уште од почетокот на 2021 година за овозможување извлекување податоци, далечинско извршување и одржување постојан пристап.

Transparent Tribe

DLL-датотеката е Remote Access Trojan (RAT) наречен ReverseRAT, кој SideCopy го користи уште од почетокот на 2021 година за овозможување извлекување податоци, далечинско извршување и одржување постојан пристап.

MITRE ATT&CK

ReverseRAT in ATT&CK

21 distinct techniques

Reporting

Research mentioning ReverseRAT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.