Skip to main content
Mallory
MalwareUsed by 3 actors

AllaKore

AllaKore is a publicly available, open-source Delphi-based remote access trojan (RAT) that has been repeatedly referenced as the upstream codebase or malware family behind multiple Latin America-focused banking trojan variants, including AllaSenha, CarnavalHeist, KL Gorki, and a 2026 variant designated NFe-RAT. Reporting describes AllaKore as frequently leveraged against users in Latin America, especially Brazil, where derived variants are used to steal online banking credentials and 2FA artifacts such as tokens and QR codes. Observed descendant campaigns used multi-stage phishing chains themed around Brazilian electronic invoices (NFS-e / NF-e), including malicious LNK files delivered via Windows search/WebDAV abuse, BAT/PowerShell launchers, embedded Python stages, and in-memory Delphi DLL payloads. Capabilities attributed in the provided content to AllaKore-derived banking variants include remote control, keyboard and mouse interaction, remote desktop functionality, keylogging, screen capture, credential theft through bank-specific overlays, and PIX QR-code fraud; one variant also included a command to terminate AnyDesk. The content also notes AllaKore use outside Latin America: Cisco Talos reported SideCopy heavily relying on Allakore RAT in campaigns targeting Indian government personnel and other entities in India, alongside other RAT families. High-confidence associations in the content therefore link AllaKore both to Brazilian banking malware ecosystems and to SideCopy operations. No standalone AllaKore-specific IOC set is provided beyond its characterization as a publicly available Delphi RAT and its role as the basis for these observed variants.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
SideCopy

"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."

via dark readingdarkreading.com
Transparent Tribe

“...including remote access trojans such as AresRAT, AllaKore, GetaRAT, Poseidon and DeskRAT...”

via ctoatncsc substackctoatncsc.substack.com
Greedy Sponge

...deliver a modified version of AllaKore RAT and SystemBC...

via cloudatg insightscloudatg.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.