AllaKore
AllaKore is a publicly available, open-source Delphi-based remote access trojan (RAT) that has been repeatedly referenced as the upstream codebase or malware family behind multiple Latin America-focused banking trojan variants, including AllaSenha, CarnavalHeist, KL Gorki, and a 2026 variant designated NFe-RAT. Reporting describes AllaKore as frequently leveraged against users in Latin America, especially Brazil, where derived variants are used to steal online banking credentials and 2FA artifacts such as tokens and QR codes. Observed descendant campaigns used multi-stage phishing chains themed around Brazilian electronic invoices (NFS-e / NF-e), including malicious LNK files delivered via Windows search/WebDAV abuse, BAT/PowerShell launchers, embedded Python stages, and in-memory Delphi DLL payloads. Capabilities attributed in the provided content to AllaKore-derived banking variants include remote control, keyboard and mouse interaction, remote desktop functionality, keylogging, screen capture, credential theft through bank-specific overlays, and PIX QR-code fraud; one variant also included a command to terminate AnyDesk. The content also notes AllaKore use outside Latin America: Cisco Talos reported SideCopy heavily relying on Allakore RAT in campaigns targeting Indian government personnel and other entities in India, alongside other RAT families. High-confidence associations in the content therefore link AllaKore both to Brazilian banking malware ecosystems and to SideCopy operations. No standalone AllaKore-specific IOC set is provided beyond its characterization as a publicly available Delphi RAT and its role as the basis for these observed variants.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
“...including remote access trojans such as AresRAT, AllaKore, GetaRAT, Poseidon and DeskRAT...”
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source RAT identified as the ultimate ancestor of the AllaSenha/CarnavalHeist/KL Gorki lineage that culminates in NFe-RAT.
RAT used in long-running campaigns targeting Mexican organizations; delivered alongside SystemBC and other loaders (per summary).
Related Posts: Greedy Sponge Reemerges: New AllaKore RAT Variant and SystemBC Target Mexico’s Financial Sector
RAT family listed as part of APT36/Transparent Tribe’s malware arsenal; no additional technical detail provided in the text.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.