ATT&CKSoftwareGravityRAT

GravityRAT

S0237

Malware.View on attack.mitre.org

About this malware

GravityRAT is a remote access tool (RAT) and has been in ongoing development since 2016. The actor behind the tool remains unknown, but two usernames have been recovered that link to the author, which are "TheMartian" and "The Invincible." According to the National Computer Emergency Response Team (CERT) of India, the malware has been identified in attacks against organization and entities in India.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1005
Data from Local System

GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf.

T1007
System Service Discovery

GravityRAT has a feature to list the available services on the system.

T1016
System Network Configuration Discovery

GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name.

T1025
Data from Removable Media

GravityRAT steals files based on an extension list if a USB drive is connected to the system.

T1027.005
Indicator Removal from Tools

The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document.

T1027.013
Encrypted/Encoded File

GravityRAT supports file encryption (AES with the key "lolomycin2017").

T1033
System Owner/User Discovery

GravityRAT collects the victim username along with other account information (account type, description, full name, SID and status).

T1047
Windows Management Instrumentation

GravityRAT collects various information via WMI requests, including CPU information in the Win32_Processor entry (Processor ID, Name, Manufacturer and the clock speed).

T1049
System Network Connections Discovery

GravityRAT uses the netstat command to find open ports on the victim’s machine.

T1053.005
Scheduled Task

GravityRAT creates a scheduled task to ensure it is re-executed everyday.

T1057
Process Discovery

GravityRAT lists the running processes on the system.

T1059.003
Windows Command Shell

GravityRAT executes commands remotely on the infected host.

T1071.001
Web Protocols

GravityRAT uses HTTP for C2.

T1082
System Information Discovery

GravityRAT collects the MAC address, computer name, and CPU information.

T1083
File and Directory Discovery

GravityRAT collects the volumes mapped on the system, and also steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf.

View all 19 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Talos GravityRAT Open source
    Mercer, W., Rascagneres, P. (2018, April 26). GravityRAT - The Two-Year Evolution Of An APT Targeting India. Retrieved May 16, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.