AresRAT is a remote access trojan associated with Transparent Tribe (APT36), a Pakistan-aligned cyberespionage threat actor. It is a Python-based implant packaged with PyInstaller as an ELF executable and is part of APT36’s Linux-oriented malware rotation, following Poseidon and preceding DeskRAT in activity reported from 2025. APT36 has historically targeted government, military, diplomatic, national-security, and defense-related organizations in South Asia, particularly India and Afghanistan. Specific AresRAT command capabilities, persistence mechanisms, and delivery methods are not currently available.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Помимо Crimson RAT, в арсенал APT36 входят DeskRAT, AresRAT, AllaKore, GetaRAT и Poseidon.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Удалённый троян, указанный как часть ротируемого инструментария APT36.
A Python/PyInstaller-based Linux ELF RAT used by APT36 prior to DeskRAT. The report notes samples compiled with PyInstaller and carrying Python runtime artifacts.
RAT family listed as part of APT36/Transparent Tribe’s historical malware arsenal; no additional technical detail provided in the text.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.