DeskRAT is a Go-based remote access trojan associated with the Pakistan-aligned Transparent Tribe (APT36, also known as Mythic Leopard) espionage group. It has been used against Indian government, defense, military, academic, and strategic organizations, with campaigns specifically targeting BOSS Linux environments. DeskRAT is delivered through targeted spearphishing, including archive attachments and cloud-hosted lures containing weaponized freedesktop launcher files or malicious PowerPoint add-ins. Linux infection chains use obfuscated shell-based staging to retrieve and execute a Go ELF implant while presenting decoy documents to the victim. DeskRAT communicates with operator infrastructure over WebSockets and supports remote command execution, file browsing and collection, additional-payload execution, persistence, and data exfiltration. Reported Linux persistence mechanisms include system services, scheduled execution, desktop autostart, and shell-startup modification. DeskRAT is part of Transparent Tribe's evolving cross-platform toolkit, alongside other remote-access malware used for long-term intelligence collection against South Asian targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Помимо Crimson RAT, в арсенал APT36 входят DeskRAT, AresRAT, AllaKore, GetaRAT и Poseidon.
The campaigns are characterized by the use of malware families like Geta RAT, Ares RAT, and DeskRAT...
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Once executed, the malicious .desktop launcher initiates a heavily obfuscated shell-based infection chain involving staged payload retrieval, inline decoding routines, and deployment of a Golang-based ELF implant tracked in this report as DeskRAT.
"DeskRAT, is delivered via a rogue PowerPoint Add-In file that runs embedded macro to establish outbound communication with a remote server to fetch the malware."
The DeskRAT payload's ASCII85+bzip2 delivery mechanism, the decoded triple-encoded bash loader ( base64 → xxd -r -p → base64 ) ...
The C2 protocol WebSocket ( ws:// over TCP/8080), gorilla/websocket implementation ... Sending a WebSocket upgrade ... all complete the handshake and receive a server-initiated JSON frame on connection
The command-and-control channel is a WebSocket endpoint on 85.137.249[.]224:8080/ws ... The agent's runtime behavior is: dial wss://<c2>:8080/ws , register with a UUIDv4 session identifier prefixed cxx- , send heartbeats, and handle RPC messages over the WebSocket channel.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Удалённый троян, указанный как часть ротируемого инструментария APT36.
A Golang-based ELF implant deployed through weaponized Linux .desktop files in a phishing campaign targeting Indian military and defense infrastructure via staged shell payload delivery.
A Go-based Linux stealer-RAT delivered via a malicious .desktop launcher and triple-encoded bash loader. The payload is fetched from a remote server, decoded from ASCII85 and bzip2, dropped into /tmp, then executed. The implant uses WebSocket C2 and is described as supporting standard RAT functions such as file listing, upload/download, command execution, heartbeats, and session registration.
Remote access trojan used in campaigns targeting Indian defense sector and government-aligned organizations; used to steal sensitive data and maintain access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.