GravityRAT is a remote access trojan and spyware family with Windows, Android, and macOS variants, used in targeted espionage against Indian individuals and organizations, including armed forces, government, defense, police, and related technology sectors. It has been active since at least 2015. Cosmic Leopard, a Pakistani threat cluster, has deployed GravityRAT in Operation Celestial Force. Android campaigns distributing the trojanized messaging applications BingeChat and Chatico have been attributed to SpaceCobra.
Windows variants collect account details, processor information, system date and time, network configuration, running processes, available services, and open-port information. They steal Office documents, PDFs, and other selected files from local storage and connected USB drives, and establish persistence through scheduled tasks that execute daily. GravityRAT employs multiple virtualization-detection techniques, including checks of computer names, CPU core counts, and hypervisor artifacts. A distinctive technique queries CPU temperature through Windows Management Instrumentation and treats unsupported or erroneous responses as evidence of virtualization, potentially suppressing or terminating execution.
Android variants collect contacts, SMS messages, call logs, location data, device identifiers, phone and SIM information, and selected files. Updated variants also steal encrypted WhatsApp backup files and accept commands to delete files, contacts, and call logs. Trojanized messaging applications can begin command-and-control communication and data exfiltration before users sign in, staging stolen information locally before uploading it over HTTPS and removing the staged copies.
Distribution includes spearphishing with malicious Office documents whose macros download the payload, as well as targeted social-media approaches that build trust before directing victims to malicious application downloads. Android deployments masquerade as legitimate messaging or utility applications and are distributed through attacker-controlled websites, including selectively accessible download sites.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET researchers have identified an updated version of Android GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico.
GravityRAT, a closed-source malware family, first disclosed by Talos in 2018, is a Windows- and Android-based RAT used to target Indian entities.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Several entries describe identifying whether the current user has admin privileges, determining privilege level, identifying groups the user belongs to, or verifying execution as SYSTEM.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
151 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-platform remote access trojan enabling persistent access to compromised devices and exfiltration/harvesting of sensitive data (e.g., documents, photos, encrypted backups), using stealth and disguising tactics.
GravityRAT is a cross-platform remote access trojan capable of data theft, including WhatsApp backups, and features advanced anti-analysis and evasion techniques. It is attributed to the Pakistan-based Transparent Tribe group.
GravityRAT is a remote access trojan (RAT) known for espionage activities across multiple platforms, enabling threat actors to exfiltrate sensitive data and maintain persistent access.
GravityRAT is a cross-platform remote access trojan (RAT) that targets Windows, Android, and macOS systems. It masquerades as legitimate software to infect devices, collects sensitive data, and exfiltrates it to remote servers. It employs advanced evasion techniques, including environmental checks and CPU temperature readings, to avoid detection and analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.