Executive Summary
GravityRAT is a sophisticated Windows RAT that offers full remote control over compromised hosts and has been linked to attacks in India since at least 2016. Its ongoing development and the lack of publicly disclosed mitigations pose significant risk to organizations with exposed network environments. Prompt detection and containment are essential to prevent data loss and lateral movement.
Enhanced Description
GravityRAT is a remote access trojan (RAT) that has been under continuous development since 2016. The malware provides attackers with full control over infected Windows hosts, enabling actions such as file manipulation, keystroke logging, and screenshot capture – typical capabilities of advanced RATs. Actors behind GravityRAT remain unidentified; however, two usernames – "TheMartian" and "The Invincible" – have been recovered and are believed to be associated with its development team. The National Computer Emergency Response Team (CERT) of India has reported a series of attacks attributed to GravityRAT against several organizations and entities in the region, indicating that the threat group actively targets Indian infrastructure. While specific technical details about persistence mechanisms or encryption strategies are not publicly disclosed for this sample, evidence aligns with standard RAT behaviors: stealthy execution, use of privileged accounts for lateral movement, and establishment of stable command‑and‑control (C2) channels. GravityRAT’s ongoing evolution suggests an intent to remain undetected by traditional security solutions and to adapt its payloads to the victim environment. The malware’s impact extends beyond data theft; it can disable endpoint defenses, exfiltrate sensitive credentials, or pivot into broader networks. Continuous monitoring for anomalous outbound traffic to known GravityRAT IP ranges, coupled with file integrity checks of commonly targeted executables, is critical for early detection.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence is limited primarily to publicly disclosed operational security notes from CERT India and the limited naming identifiers. Key technical capabilities are inferred based on typical RAT behaviors; direct evidence of these mechanisms in GravityRAT samples is not presented, creating a gap in precise attribution and detailed functionality.
GravityRAT is a remote access tool (RAT) and has been in ongoing development since 2016. The actor behind the tool remains unknown, but two usernames have been recovered that link to the author, which are "TheMartian" and "The Invincible." According to the National Computer Emergency Response Team (CERT) of India, the malware has been identified in attacks against organization and entities in India. (Citation: Talos GravityRAT)