ReverseRAT is a Windows remote-access trojan used by the Pakistan-linked SideCopy (TAG-140) threat cluster since at least early 2021. It has been deployed in espionage campaigns against Indian government, defense, critical-infrastructure, and academic targets. ReverseRAT provides remote command execution, shell access, file operations and uploads, host and installed-software discovery, screenshot capture, password theft, clipboard collection, and data exfiltration. It can establish persistence through Windows Registry autorun mechanisms and uses encrypted command-and-control communications. Observed delivery chains have used spear-phishing messages carrying weaponized archives and deceptive shortcut lures, followed by HTA execution, staged DLL loading, obfuscation, and in-memory payload reconstruction to reduce detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The DLL acts as a dropper for a batch script and a secondary exploit stage, which ultimately deploys the ReverseRAT remote access trojan.
DLL-датотеката е Remote Access Trojan (RAT) наречен ReverseRAT, кој SideCopy го користи уште од почетокот на 2021 година за овозможување извлекување податоци, далечинско извршување и одржување постојан пристап.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The HTA and final payload are obfuscated; startT.hta conducts a multi-stage deobfuscation routine to reconstruct the XAML payload.
The archives hold a Windows shortcut file (.lnk) "disguised with a PDF icon and a .DOCX extension to appear legitimate."
"The malware employs an anti-forensic routine to delete the HTA file."
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan deployed by SideCopy that collects sensitive data, remotely executes commands, maintains persistence, uses encrypted command-and-control traffic, and exfiltrates data to an IP address.
A SideCopy remote-access trojan delivered through a multi-stage spear-phishing chain. It supports system and installed-software enumeration, screenshots, password and clipboard collection, file operations, command execution, Registry-based persistence, file upload, and interactive shell access. It encrypts C2 traffic and exfiltrates collected data to its C2 server over TCP port 5863.
Remote-access trojan used by SideCopy for data exfiltration, remote command execution, persistence, file operations, shell access, and collection of system metadata, installed software, screenshots, passwords, and clipboard data. It encrypts C2 traffic with a hard-coded key and exfiltrates collected data over port 5863.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.