GravityRAT is a cross-platform remote access trojan and spyware family used in espionage operations. It has been associated with campaigns targeting the Indian armed forces and has evolved beyond Windows to include macOS variants, demonstrating sustained operator investment in multi-platform access. On macOS, observed samples have functioned as first-stage downloaders that deploy additional payloads and establish persistence through scheduled task mechanisms such as cron-based execution. Reported variants perform environmental checks before full execution, including validation of internet connectivity, virtualized environments, and user privacy-access conditions, indicating an emphasis on operational security and reliable post-compromise execution. GravityRAT is used for covert surveillance and remote control, and is best characterized as an espionage-oriented malware family rather than a ransomware or extortion operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GravityRAT is engaged in ongoing espionage campaigns across multiple platforms, likely targeting sensitive data and communications.
GravityRAT is a cross-platform remote administration tool (RAT) used for espionage, now ported to macOS. It acts as a first-stage downloader, persisting via cron jobs and downloading further payloads. It is known to target government and military organizations, particularly in India.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.