AllaKore RAT
AllaKore RAT is a publicly available Delphi-based remote access trojan. The provided content states it has been used by multiple threat actors, including SideCopy, Confucius, and a financially motivated group tracked by Arctic Wolf as Greedy Sponge. SideCopy reportedly relies heavily on AllaKore RAT in campaigns targeting government personnel and other entities in India, using infection chains that begin with malicious LNK files and progress through multiple HTAs and loader DLLs to deliver final payloads. Arctic Wolf observed Greedy Sponge targeting organizations in Mexico with malspam delivering versions of AllaKore RAT alongside SystemBC. The broader reporting also links AllaKore RAT to Confucius. Based on the content, the malware is associated with targeted intrusion activity in India, Pakistan, Mexico, and potentially broader South Asian-focused operations. No specific AllaKore RAT indicators of compromise are provided in the content, though Cisco Talos notes ClamAV detections for AllakoreRAT in relation to SideCopy activity.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Arctic Wolf has spotted a financially motivated group named Greedy Sponge target organizations in Mexico with malspam that delivers versions of AllaKore RAT and SystemBC.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered via malspam in campaigns targeting organizations in Mexico (per Arctic Wolf).
A publicly available Delphi-based remote access trojan used for remote control and data theft.
A remote access trojan used for persistent access and control, employed by Confucius.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.