AllaKore is a publicly available Delphi-based remote access trojan that has been repeatedly used as a foundation or commodity component in multiple intrusion sets. It is notably associated with campaigns targeting Latin America, especially Brazil and Mexico, and has also appeared in South Asia-focused operations linked to SideCopy. The malware’s open-source availability has enabled extensive reuse, modification, and derivative development, including banking-focused variants such as AllaSenha and later descendants in the same lineage.
AllaKore provides remote access functionality and has been used to support interactive control of infected Windows systems. Reported capabilities in AllaKore-derived campaigns include credential theft, keylogging, remote desktop or keyboard-and-mouse control, reconnaissance of host information, persistence, and exfiltration of victim data. In banking-focused variants derived from the AllaKore ecosystem, operators have implemented overlays and workflows aimed at stealing online banking credentials and two-factor authentication artifacts, including QR-code-based payment authorization data, particularly against Brazilian financial institutions.
Observed delivery chains associated with AllaKore and its variants commonly rely on phishing lures themed around Brazilian electronic invoices or tax documents, often using malicious shortcut files, script launchers, WebDAV abuse, embedded Python stages, and in-memory DLL loading to evade detection. In other operations, AllaKore has been delivered alongside other malware families such as SystemBC. SideCopy has also used AllaKore in campaigns targeting Indian government-related entities, typically through multi-stage loader chains involving malicious shortcuts and script-based execution.
The malware primarily targets Windows environments. Across campaigns, AllaKore and its descendants have been used against financial-sector victims, government personnel, and other organizations of strategic interest. Its continued appearance in active campaigns, along with the emergence of customized descendants, indicates that AllaKore remains an adaptable and operationally relevant RAT framework rather than merely a historical open-source project.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
“...including remote access trojans such as AresRAT, AllaKore, GetaRAT, Poseidon and DeskRAT...”
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Azure DevOps REST API - a totally legit Microsoft service - can be used by an attacker to communicate with their infrastructure in unexpected ways... your Azure DevOps “C2 server” is ready for abuse. | The simplest way to talk to Azure DevOps REST API is to hit an endpoint... blends with legit traffic - all calls go to dev.azure.com.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source RAT identified as the ultimate ancestor of the AllaSenha/CarnavalHeist/KL Gorki lineage that culminates in NFe-RAT.
RAT used in long-running campaigns targeting Mexican organizations; delivered alongside SystemBC and other loaders (per summary).
Related Posts: Greedy Sponge Reemerges: New AllaKore RAT Variant and SystemBC Target Mexico’s Financial Sector
RAT family listed as part of APT36/Transparent Tribe’s malware arsenal; no additional technical detail provided in the text.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.