AllaKore RAT is a publicly available Delphi-based remote access trojan. The provided content states it has been used by multiple threat actors, including SideCopy, Confucius, and a financially motivated group tracked by Arctic Wolf as Greedy Sponge. SideCopy reportedly relies heavily on AllaKore RAT in campaigns targeting government personnel and other entities in India, using infection chains that begin with malicious LNK files and progress through multiple HTAs and loader DLLs to deliver final payloads. Arctic Wolf observed Greedy Sponge targeting organizations in Mexico with malspam delivering versions of AllaKore RAT alongside SystemBC. The broader reporting also links AllaKore RAT to Confucius. Based on the content, the malware is associated with targeted intrusion activity in India, Pakistan, Mexico, and potentially broader South Asian-focused operations. No specific AllaKore RAT indicators of compromise are provided in the content, though Cisco Talos notes ClamAV detections for AllakoreRAT in relation to SideCopy activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Arctic Wolf has spotted a financially motivated group named Greedy Sponge target organizations in Mexico with malspam that delivers versions of AllaKore RAT and SystemBC.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered via malspam in campaigns targeting organizations in Mexico (per Arctic Wolf).
A publicly available Delphi-based remote access trojan used for remote control and data theft.
A remote access trojan used for persistent access and control, employed by Confucius.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.