Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware GravityRAT

GravityRAT

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

GravityRAT is a sophisticated Windows RAT that offers full remote control over compromised hosts and has been linked to attacks in India since at least 2016. Its ongoing development and the lack of publicly disclosed mitigations pose significant risk to organizations with exposed network environments. Prompt detection and containment are essential to prevent data loss and lateral movement.

Enhanced Description

GravityRAT is a remote access trojan (RAT) that has been under continuous development since 2016. The malware provides attackers with full control over infected Windows hosts, enabling actions such as file manipulation, keystroke logging, and screenshot capture – typical capabilities of advanced RATs. Actors behind GravityRAT remain unidentified; however, two usernames – "TheMartian" and "The Invincible" – have been recovered and are believed to be associated with its development team. The National Computer Emergency Response Team (CERT) of India has reported a series of attacks attributed to GravityRAT against several organizations and entities in the region, indicating that the threat group actively targets Indian infrastructure. While specific technical details about persistence mechanisms or encryption strategies are not publicly disclosed for this sample, evidence aligns with standard RAT behaviors: stealthy execution, use of privileged accounts for lateral movement, and establishment of stable command‑and‑control (C2) channels. GravityRAT’s ongoing evolution suggests an intent to remain undetected by traditional security solutions and to adapt its payloads to the victim environment. The malware’s impact extends beyond data theft; it can disable endpoint defenses, exfiltrate sensitive credentials, or pivot into broader networks. Continuous monitoring for anomalous outbound traffic to known GravityRAT IP ranges, coupled with file integrity checks of commonly targeted executables, is critical for early detection.

Key Capabilities

  • Establishes persistent remote control over infected Windows systems
  • Collects keystrokes, screenshots, and system information
  • Allows file upload/download and executes arbitrary commands
  • Maintains stealthy C2 communication, potentially using encrypted traffic
  • May disable local security tools or tamper with registry entries

ATT&CK Techniques

T1059
T1071.001
T1027
T1105

Recommended Actions

  • Deploy signature‑based detection for GravityRAT binaries and related configuration files
  • Monitor outbound network traffic for known C2 IP addresses or domains identified by CERT India
  • Inspect Windows event logs for persistence changes such as new scheduled tasks or registry modifications
  • Use endpoint detection and response (EDR) to flag fileless execution patterns and command‑line activity consistent with RATs
  • Implement strong access controls and least privilege policies to limit lateral movement opportunities

Suggested Tags

remote-access-trojan
gravityrat
india-target
unknown-actor
windows-threat
persistent

Confidence Assessment

The intelligence is limited primarily to publicly disclosed operational security notes from CERT India and the limited naming identifiers. Key technical capabilities are inferred based on typical RAT behaviors; direct evidence of these mechanisms in GravityRAT samples is not presented, creating a gap in precise attribution and detailed functionality.

Description

GravityRAT is a remote access tool (RAT) and has been in ongoing development since 2016. The actor behind the tool remains unknown, but two usernames have been recovered that link to the author, which are "TheMartian" and "The Invincible." According to the National Computer Emergency Response Team (CERT) of India, the malware has been identified in attacks against organization and entities in India. (Citation: Talos GravityRAT)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.