GravityRAT is a closed-source remote access trojan and spyware family associated with long-running espionage activity primarily targeting Indian individuals and organizations, including defense, government, police, and related technology sectors. Reporting has linked its operations to Pakistan-aligned threat activity, including clusters tracked as Cosmic Leopard and SpaceCobra, though some broader actor relationships remain unconfirmed. The malware has evolved from early Windows-focused intrusions into a multi-platform family with Windows and Android variants, and reporting also notes macOS-related variants within the broader campaign ecosystem.
On Windows, GravityRAT functions as a RAT with host reconnaissance, surveillance, and file-theft capabilities. Documented behavior includes enumerating running processes and services, collecting user-account details such as username and account metadata, gathering network configuration information including IP address, MAC address, and domain context, querying system date and time, and collecting processor information through WMI. It steals documents matching predefined extension lists and can monitor for removable media, collecting targeted files when USB storage is connected. Persistence has been observed through scheduled tasks configured to relaunch the malware regularly. Earlier delivery chains used malicious Microsoft Office documents, likely distributed by email, that downloaded the payload when macros were enabled. GravityRAT has also been noted for extensive anti-analysis and anti-virtualization checks.
On Android, GravityRAT has been distributed through trojanized applications, especially messaging and utility-themed apps, including highly targeted campaigns involving fake or gated chat platforms. Android variants have been observed collecting device identifiers, phone and SIM information, SMS messages, contacts, call logs, location-related data, build information, and files from device and external storage, including encrypted WhatsApp backup files in newer versions. Some Android variants stage stolen data locally before exfiltration and can receive commands to delete files, contacts, and call logs, indicating both surveillance and cleanup capabilities. Campaigns have relied on social engineering, spearphishing, malicious websites, and fake installers or trojanized apps to reach victims.
GravityRAT has been used as part of broader intrusion ecosystems alongside supporting loaders and administration tooling, enabling operators to manage infections across multiple concurrent campaigns. Its combination of targeted delivery, persistence, reconnaissance, surveillance, and document theft makes it a notable espionage malware family focused on long-term access and intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET researchers have identified an updated version of Android GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico.
GravityRAT, a closed-source malware family, first disclosed by Talos in 2018, is a Windows- and Android-based RAT used to target Indian entities.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
This campaign primarily utilizes two infection vectors — spear phishing and social engineering. Spear phishing consists of messages sent to targets with pertinent language and maldocs that contain malware such as GravityRAT.
Spear phishing consists of messages sent to targets with pertinent language and maldocs that contain malware such as GravityRAT.
The other infection vector, gaining popularity in this operation, and now a staple tactic of the Cosmic Leopard’s operations consists of contacting targets over social media channels, establishing trust with them and eventually sending them a malicious link to download either the Windows- or Android-based GravityRAT or the Windows-based loader, HeavyLift.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The latest variants of GravityRAT are distributed through malicious websites, some registered and set up as late as early January 2024, pretending to distribute legitimate Android applications.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Several entries describe identifying whether the current user has admin privileges, determining privilege level, identifying groups the user belongs to, or verifying execution as SYSTEM.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Examples include 'Caterpillar WebShell can obtain a list of user accounts from a victim's machine,' 'DRATzarus can obtain a list of users from an infected machine,' 'Woody RAT can retrieve a list of user accounts and usernames from an infected machine,' and 'TrickBot can identify the user and groups the user belongs to on a compromised host.'
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
The GravityRAT Remote Access Trojan (or Tool) is noteworthy for the fact that is uses no fewer than seven techniques to detect whether it is running inside a virtual machine.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
150 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-platform remote access trojan enabling persistent access to compromised devices and exfiltration/harvesting of sensitive data (e.g., documents, photos, encrypted backups), using stealth and disguising tactics.
GravityRAT is a cross-platform remote access trojan capable of data theft, including WhatsApp backups, and features advanced anti-analysis and evasion techniques. It is attributed to the Pakistan-based Transparent Tribe group.
GravityRAT is a remote access trojan (RAT) known for espionage activities across multiple platforms, enabling threat actors to exfiltrate sensitive data and maintain persistent access.
GravityRAT is a cross-platform remote access trojan (RAT) that targets Windows, Android, and macOS systems. It masquerades as legitimate software to infect devices, collects sensitive data, and exfiltrates it to remote servers. It employs advanced evasion techniques, including environmental checks and CPU temperature readings, to avoid detection and analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.