DRAT is a remote access trojan used in espionage-oriented intrusions and publicly referenced alongside other commodity and semi-custom RATs. A later variant, DRAT V2, has been associated with TAG-140 activity assessed to overlap with SideCopy, an operational subgroup or affiliate linked to Transparent Tribe, a suspected Pakistani state-aligned threat actor. Observed targeting has included Indian government and related organizations, with reporting also noting defense, maritime, academic, railway, oil and gas, and external affairs-linked entities.
Recent reporting describes an evolution from an earlier .NET-based DRAT implementation to a Delphi-compiled DRAT V2. This newer variant uses a custom TCP-based, server-initiated command-and-control protocol and is intended to provide persistent remote control of compromised systems. Documented capabilities include reconnaissance, data exfiltration, and upload of additional payloads, enabling both automated and interactive post-exploitation activity.
Observed intrusion chains delivering DRAT V2 used social engineering themed around spoofed Indian government content, including ClickFix-style lures that induced victims to execute a malicious script through mshta.exe. In the reported activity, execution led to the BroaderAspect .NET loader, which established persistence and then installed and launched DRAT V2. DRAT V2 has been characterized as using relatively basic infection and persistence methods while remaining operationally effective as a flexible remote access tool on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The deployment of DRAT V2 reflects TAG-140's ongoing refinement of its remote access tooling, transitioning from a .NET-based version of DRAT to a new Delphi-compiled variant"
"The deployment of DRAT V2 reflects TAG-140's ongoing refinement of its remote access tooling, transitioning from a .NET-based version of DRAT to a new Delphi-compiled variant"
6 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modified RAT used in campaigns targeting Indian government/defense/rail sectors (per summary).
Remote access trojan used to provide attackers interactive access/control over compromised systems (modified variant referenced as DRAT V2).
Remote access trojan used to maintain persistent control of infected systems; V2 updates a custom TCP-based, server-initiated C2 protocol and supports actions including data exfiltration, uploading additional payloads, and reconnaissance.
A RAT mentioned only as background context alongside other attacker tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.