s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.gravity_rat

📛 Threat Title

Malware family: Gravity RAT

Category: Gravity RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.gravity_rat`. Printable name: Gravity RAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:any.run

    GravityRAT malware uses CPU temperature checks to evade detection while conducting cross-platform espionage, targeting government and military organizations through sophisticated social engineering and patient relationship-building tactics.

  • web:attack.mitre.org

    GravityRAT is a remote access tool ( RAT ) and has been in ongoing development since 2016. The actor behind the tool remains unknown, but two usernames have been recovered that link to the author, which are "TheMartian" and "The Invincible." According to the National Computer Emergency Response Team (CERT) of India, the malware has been identified in attacks against organization and entities in ...

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as GravityRAT .

  • web:blog.sucuri.net

    Learn what a Remote Access Trojan is, how RATs work, the risks they pose, and how to protect against infections. We cover the basics, examine real incidents where websites spread RAT infections, and provide practical advice for securing your devices against a RAT .

  • web:cyberpress.org

    GravityRAT remote access attacks - A long-running espionage campaign using GravityRAT , a remote access trojan ( RAT ) linked to Pakistan-based.

  • web:cybersecuritynews.com

    The malware then begins collecting sensitive information, including documents, photos, messages, and WhatsApp backups. This stolen data gets sent to hackers who control the malware from remote servers. Any.Run analysts identified that GravityRAT uses clever tricks to avoid getting caught by security tools.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Gravity RAT malware family including references, samples and yara signatures.

  • web:medium.com

    GravityRAT : Malware Overview GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016.

  • web:thehackernews.com

    An updated version of an Android remote access trojan dubbed GravityRAT has been found masquerading as messaging apps BingeChat and Chatico as part of a narrowly targeted campaign since June 2022. "Notable in the newly discovered campaign, GravityRAT can exfiltrate WhatsApp backups and receive ...

  • web:www.keysight.com

    This blogs looks in the GravityRAT android malware from the source code and network communication point of view.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.