TF-MAL-apk.gravity_rat
📛 Threat Title
Malware family: Gravity RAT
Description
ThreatFox malware family `apk.gravity_rat`. Printable name: Gravity RAT.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
GravityRAT malware uses CPU temperature checks to evade detection while conducting cross-platform espionage, targeting government and military organizations through sophisticated social engineering and patient relationship-building tactics.
-
web:attack.mitre.org
GravityRAT is a remote access tool ( RAT ) and has been in ongoing development since 2016. The actor behind the tool remains unknown, but two usernames have been recovered that link to the author, which are "TheMartian" and "The Invincible." According to the National Computer Emergency Response Team (CERT) of India, the malware has been identified in attacks against organization and entities in ...
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as GravityRAT .
-
web:blog.sucuri.net
Learn what a Remote Access Trojan is, how RATs work, the risks they pose, and how to protect against infections. We cover the basics, examine real incidents where websites spread RAT infections, and provide practical advice for securing your devices against a RAT .
-
web:cyberpress.org
GravityRAT remote access attacks - A long-running espionage campaign using GravityRAT , a remote access trojan ( RAT ) linked to Pakistan-based.
-
web:cybersecuritynews.com
The malware then begins collecting sensitive information, including documents, photos, messages, and WhatsApp backups. This stolen data gets sent to hackers who control the malware from remote servers. Any.Run analysts identified that GravityRAT uses clever tricks to avoid getting caught by security tools.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Gravity RAT malware family including references, samples and yara signatures.
-
web:medium.com
GravityRAT : Malware Overview GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016.
-
web:thehackernews.com
An updated version of an Android remote access trojan dubbed GravityRAT has been found masquerading as messaging apps BingeChat and Chatico as part of a narrowly targeted campaign since June 2022. "Notable in the newly discovered campaign, GravityRAT can exfiltrate WhatsApp backups and receive ...
-
web:www.keysight.com
This blogs looks in the GravityRAT android malware from the source code and network communication point of view.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.