AllaKore RAT is a publicly available Delphi-based remote access trojan that has been repeatedly used and modified by South Asian threat actors, most notably SideCopy, and has also been associated with Confucius. In SideCopy operations, modified AllaKore RAT variants have been deployed in espionage campaigns targeting Indian government, military, and defense-related entities, often using Ministry of Defence and other defense-themed lures. Observed delivery chains commonly begin with spearphishing archives containing malicious shortcut files that invoke MSHTA and staged HTA or DLL components, sometimes using DLL sideloading to launch the final RAT payload and establish persistence on compromised Windows systems.
Documented capabilities of AllaKore RAT include remote control of infected hosts, collection of system information, file and folder enumeration, file upload and download, execution of additional files, keylogging, screenshot capture, and theft of clipboard data. In SideCopy intrusions, the malware has also been integrated into multi-stage, environment-aware workflows that check installed antivirus products and alter execution paths accordingly. Campaign reporting indicates the malware has been deployed at scale against victims in India and has formed a recurring part of SideCopy's malware arsenal alongside other custom and commodity RATs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The released simsre.exe is a AllaKore RAT (also known as Cyrus) commonly used by SideCopy. Its source code is open source on GitHub and has been modified by the SideCopy group as part of its own arsenal.
Arctic Wolf has spotted a financially motivated group named Greedy Sponge target organizations in Mexico with malspam that delivers versions of AllaKore RAT and SystemBC.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
As discussed in the analysis by QiAnXin, spear phishing was used as the initial delivery method for this campaign.
The downloaded HTA files are similar to Phase One. They load DLL in memory and first collect information of installed antivirus software in the system using WMI.
During the execution, a bat file is generated, which adds a startup item for the crezly.exe program through the registry.
to download a piece of JS code to execute. Its main function is to load DLL in memory, decrypt the embedded data in the JS code through the functions in the DLL
The stage-1 HTA contains two embedded files... that are base64 encoded... Both the HTA contain embedded files...
The DLL files dropped are not sideloaded by the AllaKore RAT, and they are legitimate files... These are Microsoft Windows-related libraries...
Spear-phishing starts with an archive file containing a shortcut (LNK) in a double-extension format.
The stage-1 HTA contains two embedded files, a decoy and a DLL, that are base64 encoded.
Persistence on the final payload is set beforehand via the Run registry key.
A connection ID based on the system information is created for each instance... getinfo Send username, machine name and OS information
uploads it to “https://kcps.edu[.]in/css/fonts/files/avena/” using the POST method
Opening the LNK triggers the MSHTA process, which executes a remote HTA file hosted on a compromised domain.
106 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered via malspam in campaigns targeting organizations in Mexico (per Arctic Wolf).
A Delphi-based remote access trojan used by SideCopy that gathers system information, enumerates files and folders, uploads and executes files, logs keystrokes, steals clipboard data, and maintains C2 communications with separate sockets and persistence via Run registry keys.
An open-source remote access tool modified for SideCopy operations. The content says it supports keylogging, screenshot capture, remote access, and uploading stolen information to command-and-control servers.
An open-source remote access trojan modified and used by SideCopy. In this campaign it is delivered as simsre.exe and supports keylogging, screenshots, file browsing, file upload/download, clipboard theft, wallpaper changes, and remote control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.