GravityRAT

MITRE ATT&CK: S0237 View on attack.mitre.org

Aliases: GravityRAT

First seen
2016-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
525 (525 malicious)
Last IoC activity
2026-09-02 03:34:26
Profile updated
2026-07-07 15:04:20

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:in

Context

GravityRAT is a remote access tool (RAT) and has been in ongoing development since 2016. The actor behind the tool remains unknown, but two usernames have been recovered that link to the author, which are "TheMartian" and "The Invincible." According to the National Computer Emergency Response Team (CERT) of India, the malware has been identified in attacks against organization and entities in India.

Recent IoC activity

541 malicious indicators in Maltiverse are attributed to GravityRAT (S0237). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-09-02_d283f6682f1695d567912affab1aebb9_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_81e13603d4c870944a8332dfdf9502af_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_84896cc7971b1d6843061f06320b637c_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_93a1da9ea480a356df67516f20ea4109_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_a01a9255f26f8c084d1d6b6ac9ffd17d_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_a03e4681805e1a27b2387013789ef59a_coinminer_glassworm_poet-rat_sliv... 2026-09-02 1
file sample 2026-09-01_a0815b96a7b715bed07dd6bee256a387_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_a1f9a0c02e158f9b6c99645ac9de4b27_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_ab518f20691cd02f3839d6aaf024f8fa_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_aef47fc813d7a553c03f5987ff3b755e_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_b234de3ff30e38bc3416e516dea2ed7b_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_b7e2637ea9c57d9e1f0980d4ccea50bd_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_c15f626174ba4fa866451b1dee01972a_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_c2e8c4ef7b22a009434005352116b472_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_c60a95893943f00918b78320d9be46c2_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_cf6ece21541650d7f971571c4d1d2738_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_d6b32b733e5506b97aae77a08bdee81c_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_d8bf94af3fed92856a3c3e083647fe65_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_d9f234b3f1137d832352b16bded3fd77_cobalt-strike_coinminer_glassworm... 2026-09-02 1
file sample 2026-09-01_da2bb4d25989f2eb55a576eb1c65e1bf_cobalt-strike_coinminer_glassworm... 2026-09-02 1

Detection coverage

  • 1 YARA rules
  • 276 Sigma rules

Malware & tools used

  • Indicator Removal from Tools (attack-pattern)
  • System Information Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Web Protocols (attack-pattern)
  • Process Discovery (attack-pattern)
  • Data from Removable Media (attack-pattern)
  • System Checks (attack-pattern)
  • Scheduled Task (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Dynamic Data Exchange (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)

Detection rules

  • DITEKSHEN_MALWARE_Win_Gravityrat (yara-rule)

Reports & references

  • Cisco Talos — Gravityrat Two Year Evolution Of Apt (report)
  • MITRE ATT&CK — S0237 (report)

External references