ReverseRAT
- First seen
- 2021-09-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-13 02:07:01
- Profile updated
- 2026-07-07 13:49:53
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:pk country_code:in
Context
ReverseRAT is a remote access trojan primarily used for espionage operations. It targets entities in South Asia, specifically within governmental and technological sectors, to exfiltrate sensitive information.
Detection coverage
- 3 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Reverserat (yara-rule)
- SEKOIA_Apt_Sidecopy_Reverserat_Strings (yara-rule)
- SEKOIA_Rat_Win_Reverserat (yara-rule)
Reports & references
- s3.amazonaws.com — 062521 Sidecopy %281%29 (report)
- seqrite.com — Umbrella Of Pakistani Threats Converging Tactics Of Cyber Operations Targeting India (report)
- threatmon.io — Apt Sidecopy Targeting Indian Government Entities (report)
- ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
- seqrite.com — Whitepaper Operationsidecopy (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Reverse Rat (report)
- blog.lumen.com — Suspected Pakistani Actor Compromises Indian Power Company With New Reverserat (report)
- blog.lumen.com — Reverserat Reemerges With A Nightfury New Campaign And New Developments Same Familiar Side Actor (report)