Netskope Threat Labs

GravityRAT

ATP Sandbox Adv. HeuristicsAVNetskope IPS

GravityRAT is a remote access tool in ongoing development since 2016, which Indian authorities have identified in attacks against organizations in India. The actor behind it remains unknown, though researchers have published recovered usernames linked to the author.

First seen
April 2022
Last seen
October 2026

19 techniques across 5 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

  • T1007System Service Discovery
  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1049System Network Connections Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1124System Time Discovery

TA0009 Collection

  • T1005Data from Local System
  • T1025Data from Removable Media

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Trojan.GravityRAT
Gen:Variant.GravityRAT.2
Gen:Variant.GravityRAT.5
Trojan.GravityRAT.1
Trojan.GravityRAT.11
Trojan.GravityRAT.12
Trojan.GravityRAT.3
Trojan.GravityRAT.4
Trojan.GravityRAT.7
Trojan.GravityRAT.9