Description
GravityRAT is a remote access tool in ongoing development since 2016, which Indian authorities have identified in attacks against organizations in India. The actor behind it remains unknown, though researchers have published recovered usernames linked to the author.
Stats
- First seen
- April 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
19 techniques across 5 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.GravityRAT |
| Gen:Variant.GravityRAT.2 |
| Gen:Variant.GravityRAT.5 |
| Trojan.GravityRAT.1 |
| Trojan.GravityRAT.11 |
| Trojan.GravityRAT.12 |
| Trojan.GravityRAT.3 |
| Trojan.GravityRAT.4 |
| Trojan.GravityRAT.7 |
| Trojan.GravityRAT.9 |