ReverseRAT

First seen
2021-09-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-13 02:07:01
Profile updated
2026-07-07 13:49:53

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:pk country_code:in

Context

ReverseRAT is a remote access trojan primarily used for espionage operations. It targets entities in South Asia, specifically within governmental and technological sectors, to exfiltrate sensitive information.

Detection coverage

  • 3 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Reverserat (yara-rule)
  • SEKOIA_Apt_Sidecopy_Reverserat_Strings (yara-rule)
  • SEKOIA_Rat_Win_Reverserat (yara-rule)

Reports & references

  • s3.amazonaws.com — 062521 Sidecopy %281%29 (report)
  • seqrite.com — Umbrella Of Pakistani Threats Converging Tactics Of Cyber Operations Targeting India (report)
  • threatmon.io — Apt Sidecopy Targeting Indian Government Entities (report)
  • ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
  • seqrite.com — Whitepaper Operationsidecopy (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Reverse Rat (report)
  • blog.lumen.com — Suspected Pakistani Actor Compromises Indian Power Company With New Reverserat (report)
  • blog.lumen.com — Reverserat Reemerges With A Nightfury New Campaign And New Developments Same Familiar Side Actor (report)

External references