RIPTIDE is a remote access trojan associated with APT12. It is used for command-and-control over HTTP, with communications protected using RC4-encrypted payloads. As a RAT, RIPTIDE enables remote post-compromise control of infected systems and fits into espionage-oriented intrusion activity attributed to Chinese state-linked operations. High-confidence reporting ties it to Windows-focused intrusions conducted by APT12.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT12 has used the RIPTIDE RAT, which communicates over HTTP with a payload encrypted with RC4.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The architecture is a proxy chain: customer traffic arrives at Riptide, which forwards it through upstream SOCKS5 or HTTP proxies -- likely residential or compromised endpoints. The upstreamselector package handles rotation and load balancing across the upstream pool.
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan that communicates over HTTP with RC4-encrypted payloads.
RAT that uses HTTP for C2 communications.
Remote access trojan that communicates over HTTP with RC4-encrypted payloads.
RAT that communicates over HTTP and encrypts payloads using RC4.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.