Last seven days
- First activity
- Sep 22, 2026
- Last activity
- Sep 22, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 2 hostnames
ReverseRAT is a custom C# remote access trojan used by the Pakistan-linked SideCopy (TAG-140) threat cluster since at least early 2021.
Profile source: Mallory opens in a new tabReverseRAT
ReverseRAT is a custom C# remote access trojan used by the Pakistan-linked SideCopy (TAG-140) threat cluster since at least early 2021. It has been deployed against Indian government, defense, critical-infrastructure, and academic targets, commonly through spear-phishing campaigns using weaponized archives, deceptive Windows shortcut lures, and HTML Application stages executed through mshta.exe. ReverseRAT supports host and installed-software discovery, screenshot capture, password and clipboard theft, file manipulation, command execution, file upload, and interactive shell access. It can establish Registry-based persistence and uses encrypted command-and-control communications. Observed infection chains employ staged payload delivery, reflective DLL loading, in-memory reconstruction and execution, obfuscation, and artifact deletion to hinder file-based detection. ReverseRAT also supports downloading and executing additional payloads, self-updating, and self-termination.
Reported operators
DLL-датотеката е Remote Access Trojan (RAT) наречен ReverseRAT, кој SideCopy го користи уште од почетокот на 2021 година за овозможување извлекување податоци, далечинско извршување и одржување постојан пристап.
DLL-датотеката е Remote Access Trojan (RAT) наречен ReverseRAT, кој SideCopy го користи уште од почетокот на 2021 година за овозможување извлекување податоци, далечинско извршување и одржување постојан пристап.
MITRE ATT&CK
Reporting
Pakistan-linked APT group SideCopy (also tracked as TAG-140) has expanded beyond its established focus on Indian government and defense organizations to target Indian academic institutions. Spear-phishing emails deliver ZIP archives containing a Windows LNK shortcut masquerading as a DOCX/PDF document; opening it retrieves an HTA payload from docsportal[.]in and launches it using the legitimate mshta.exe utility. The multi-stage chain employs reflective DLL loading, .NET deserialization, in-memory payload execution, obfuscation, registry-based persistence, and self-deletion to limit file-based detection. The final ReverseRAT implant can collect system, user, credential, clipboard, and screenshot data; execute commands; manipulate files; open a shell; and exfiltrate data through encrypted C2 traffic over port 5863 to dns.educationportals[.]biz, which resolves to 45.61.157[.]22.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.