Action RAT is a Windows remote access trojan associated with SideCopy, a Pakistan-linked espionage threat actor that has persistently targeted Indian government, military, and defense organizations. It has been observed in spearphishing campaigns using defense-themed and other tailored lures, including malicious archive and shortcut-based infection chains that invoke MSHTA and abuse DLL sideloading with legitimate executables such as credwiz.exe to evade detection. In earlier observed chains, the malware was dropped alongside a benign executable used to sideload the RAT.
The malware supports core remote-access functionality including receiving commands from command-and-control infrastructure, collecting host information, downloading and executing additional payloads, and uploading data from the victim system. Documented reconnaissance behavior includes collecting the current username, hostname, operating system version, operating system architecture, and drive and file information. It also performs security software discovery on Windows by using WMI queries against SecurityCenter2 to identify installed antivirus products, indicating both host profiling and defense-evasion awareness.
Action RAT has also been observed as part of multi-stage SideCopy operations in which multiple variants were deployed together, including campaigns where one variant downloaded and executed a larger follow-on variant. That larger variant was used to exfiltrate documents and images from common user data locations. The malware has been linked to campaigns focused on Indian victims, especially within the defense sector, and forms part of a broader SideCopy toolset that has also included modified AllaKore RAT variants and other custom remote-access malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The first tool, identified as Action RAT in analysis by Cyble, is dropped onto the victim machine alongside a benign executable which is used to sideload it, in order to avoid detection.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
As discussed in the analysis by QiAnXin, spear phishing was used as the initial delivery method for this campaign.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Action RAT’s capabilities include the ability to receive commands from the C2 server... and to upload information back to the C2.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A RAT previously used by SideCopy and referenced here as an earlier payload replaced in these campaigns by AllaKore RAT.
A remote access trojan used in SideCopy infection chains. The observed variants are deployed via phishing-delivered archives and LNK/MSHTA execution, with one variant downloading and executing a larger payload that exfiltrates documents and images from Desktop, Documents, and Downloads folders.
A remote access trojan used in the same SideCopy campaign. The content says it can receive commands from C2, collect victim information, execute additional payloads, and upload data back to the server.
Remote access trojan capable of collecting the username from an infected host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.