GravityRAT
MITRE ATT&CK: S0237 View on attack.mitre.org
Aliases: GravityRAT
- First seen
- 2016-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 525 (525 malicious)
- Last IoC activity
- 2026-09-02 03:34:26
- Profile updated
- 2026-07-07 15:04:20
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:in
Context
GravityRAT is a remote access tool (RAT) and has been in ongoing development since 2016. The actor behind the tool remains unknown, but two usernames have been recovered that link to the author, which are "TheMartian" and "The Invincible." According to the National Computer Emergency Response Team (CERT) of India, the malware has been identified in attacks against organization and entities in India.
Recent IoC activity
541 malicious indicators in Maltiverse are attributed to GravityRAT (S0237). The 20 most recently updated:
Detection coverage
- 1 YARA rules
- 276 Sigma rules
Malware & tools used
- Indicator Removal from Tools (attack-pattern)
- System Information Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- System Time Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Web Protocols (attack-pattern)
- Process Discovery (attack-pattern)
- Data from Removable Media (attack-pattern)
- System Checks (attack-pattern)
- Scheduled Task (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Service Discovery (attack-pattern)
- Data from Local System (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Dynamic Data Exchange (attack-pattern)
- Non-Standard Port (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
Detection rules
- DITEKSHEN_MALWARE_Win_Gravityrat (yara-rule)
Reports & references
- Cisco Talos — Gravityrat Two Year Evolution Of Apt (report)
- MITRE ATT&CK — S0237 (report)