GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf.2
tool
GravityRAT S0237
- Type
- malware
- Platform
- Windows
- Created
- 17 October 2018
- Last modified
- 11 April 2024
GravityRAT is a remote access tool (RAT) and has been in ongoing development since 2016. The actor behind the tool remains unknown, but two usernames have been recovered that link to the author, which are "TheMartian" and "The Invincible." According to the National Computer Emergency Response Team (CERT) of India, the malware has been identified in attacks against organization and entities in India. [1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0237
GravityRAT has a feature to list the available services on the system.3
GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name.4
GravityRAT steals files based on an extension list if a USB drive is connected to the system.5
The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document.6
GravityRAT supports file encryption (AES with the key "lolomycin2017").7
Standing S0237
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
77th percentile · 77% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
68th percentile · 68% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
40th percentile · 60% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S0237
475 distinct rules cover the 19 techniques recorded for this tool. The 515 technique-to-rule mappings resolve to 475 distinct rules, because one rule can cover several techniques. 332 Sigma · 143 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org