Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 3 actors

Desk RAT

Desk RAT is a Go-based remote access trojan observed in campaigns attributed to the Transparent Tribe (APT36) espionage ecosystem and the closely aligned SideCopy cluster. It has been delivered via malicious PowerPoint Add-In files (PPAM). Reported functionality includes collecting detailed host telemetry and system diagnostics from compromised machines, and communicating with operators over WebSocket-based command-and-control, including structured heartbeat and client information exchanges. The malware was reported alongside other RATs used in campaigns targeting Indian defense and government-aligned organizations, reflecting a broader emphasis on stealthy, persistent, long-term intelligence collection and cross-platform surveillance. High-confidence delivery and behavioral details directly mentioned in the content are the PPAM infection vector, host telemetry collection, system diagnostics gathering, and WebSocket C2 communications.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Transparent Tribe (APT36)

The report analyzes three RATs recently used by the group in attacks, namely Geta, Ares, and Desk RAT.

via risky biz rssnews.risky.biz
Transparent Tribe

Aryaka Threat Research Labs also observed campaigns delivering Desk RAT, a Go-based remote access trojan distributed via a malicious PowerPoint Add-In (PPAM).

via aryakaaryaka.com
SideCopy

Additionally, an emerging tool named Desk RAT, distributed via malicious PowerPoint Add-Ins, highlights the group’s ongoing innovation in surveillance.

via cyber security newscybersecuritynews.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence1

"These actors rely on proven tactics like spear-phishing and weaponized documents... One campaign targeted Windows systems using phishing emails ... that delivered malicious files"

Execution

1 technique
T1204User ExecutionEvidence1

"...spear-phishing and weaponized documents to quietly embed themselves in target environments."

Persistence

1 technique
T1137.006Add-insEvidence1

"...Desk RAT, distributed via malicious PowerPoint Add-Ins"

Discovery

1 technique
T1082System Information DiscoveryEvidence1

Once deployed, ARES RAT performed automated system profiling, recursive file enumeration, and structured data exfiltration.

Command and Control

1 technique
T1071Application Layer ProtocolEvidence1

Cross-platform payloads, memory-resident execution, and increasingly covert command-andcontrol channels now form the backbone of an ecosystem designed for patience rather than speed... It collects detailed system diagnostics and communicates with its operators using WebSocket-based command-and-control, exchanging structured heartbeat and client information messages.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.