AllaKore
- First seen
- 2015-01-01 00:00:00
- Malware type
- rat
- Profile updated
- 2026-07-07 13:00:23
Context
AllaKore is a simple Remote Access Tool written in Delphi, first observed in 2015 but still in early stages of development. It implements the RFB protocol which uses frame buffers and thus is able to send back only the changes of screen frames to the controller, speeding up the transport and visualization control.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Allakore (yara-rule)
Reports & references
- Cisco Talos — Sidecopy (report)
- sebdraven.medium.com — Copy Cat Of Apt Sidewinder 1893059Ca68D (report)
- s3.amazonaws.com — 062521 Sidecopy %281%29 (report)
- s3.amazonaws.com — 062521 Sidecopy %281%29 (report)
- s3.amazonaws.com — Hashes Iocs For Coverage.Txt (report)
- s3.amazonaws.com — Network Iocs List For Coverage.Txt (report)
- seqrite.com — Umbrella Of Pakistani Threats Converging Tactics Of Cyber Operations Targeting India (report)
- seqrite.com — Seqrite Whitepaper Operation Sidecopy (report)
- ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
- seqrite.com — Sidecopys Multi Platform Onslaught Leveraging Winrar Zero Day And Linux Variant Of Ares Rat (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Allakore (report)
- cocomelonc.github.io — Malware Tricks 49 (report)
- arcticwolf.com — Greedy Sponge Targets Mexico With Allakore Rat And Systembc (report)
- team-cymru.com — Allakore D The Sidecopy Train (report)
- harfanglab.io — Allasenha Allakore Variant Azure C2 Steal Banking Latin America (report)
- threatmon.io — The Anatomy Of A Sidecopy Attack From Rar Exploits To Allakore Rat (report)
- seqrite.com — Pakistani Apts Escalate Attacks On Indian Gov Seqrite Labs Unveils Threats And Connections (report)
- github.com — Allakore (report)
- twitter.com — 1212070711206064131 (report)