AllaKore is a publicly available, Delphi-based remote access trojan. It has been used by the SideCopy threat group, including in campaigns targeting government personnel and other organizations in India and Pakistan. Transparent Tribe (APT36) has also used AllaKore among a broader arsenal of remote access trojans in South Asian espionage operations. Custom banking-malware variants in the AllaKore ecosystem, including AllaSenha and CarnavalHeist-related tooling, have targeted Brazilian financial institutions, but those variants have distinct functionality and should not be treated as equivalent to the base AllaKore RAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Помимо Crimson RAT, в арсенал APT36 входят DeskRAT, AresRAT, AllaKore, GetaRAT и Poseidon.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Azure DevOps REST API - a totally legit Microsoft service - can be used by an attacker to communicate with their infrastructure in unexpected ways... your Azure DevOps “C2 server” is ready for abuse. | The simplest way to talk to Azure DevOps REST API is to hit an endpoint... blends with legit traffic - all calls go to dev.azure.com.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Удалённый троян, указанный как часть ротируемого инструментария APT36.
Referenced as a comparative Windows malware operation showing similar use of PDF lures, WebDAV, and batch scripts in multi-stage compromise chains.
Open-source RAT identified as the ultimate ancestor of the AllaSenha/CarnavalHeist/KL Gorki lineage that culminates in NFe-RAT.
RAT used in long-running campaigns targeting Mexican organizations; delivered alongside SystemBC and other loaders (per summary).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.