Skip to main content
Mallory
MalwareUsed by 3 actors

Ares RAT

Ares RAT is a Python-based remote access trojan historically associated with Transparent Tribe (APT36) and referenced in campaigns linked to the aligned SideCopy ecosystem. Reporting in the provided content describes its use in cross-platform espionage operations targeting Indian defense-sector, government, and government-aligned organizations, particularly in Linux-focused intrusion chains. In the observed Linux campaign, a Go-based downloader or Go binary, together with a downloaded shell script, installed Ares RAT. Once deployed, it performed automated system profiling, recursive file enumeration, command execution, harvesting of sensitive data, execution of Python scripts or actor-issued Python commands, and structured data exfiltration. Persistence on Linux was achieved through systemd user services, allowing the malware to survive reboots while blending into normal operations. The broader campaigns relied on phishing emails, malicious attachments or embedded download links, and multi-stage delivery chains. The content also notes that prior campaigns by the SloppyLemming cluster leveraged Ares RAT, but the detailed operational association in the supplied material is strongest with Transparent Tribe/APT36 and SideCopy. High-confidence behavioral indicators mentioned include use on Linux hosts, deployment via a Go-based downloader and shell script, automated host profiling, recursive file enumeration, structured exfiltration, and persistence through systemd user services.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Transparent Tribe

This operation used a Go-based downloader to install ARES RAT, a Python-based remote access tool historically associated with APT36 activity. Once deployed, ARES RAT performed automated system profiling, recursive file enumeration, and structured data exfiltration.

via aryakaaryaka.com
SideCopy

"Running parallel to this Windows-focused campaign is a Linux variant... to drop a Python-based Ares RAT..."

via the hacker newsthehackernews.com
SloppyLemming

"Prior campaigns ... have leveraged malware families like Ares RAT..."

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence2

"These actors rely on proven tactics like spear-phishing and weaponized documents... One campaign targeted Windows systems using phishing emails ... that delivered malicious files"

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1
TacticExecution

"...run arbitrary shell commands..."

T1204User ExecutionEvidence1
TacticExecution

"...spear-phishing and weaponized documents to quietly embed themselves in target environments."

Persistence

1 technique
T1543.002Systemd ServiceEvidence2

Persistence was achieved through systemd user services, allowing the malware to survive reboots while blending into normal system operations.

T1543.002Systemd ServiceEvidence2

Persistence was achieved through systemd user services, allowing the malware to survive reboots while blending into normal system operations.

Discovery

2 techniques
T1082System Information DiscoveryEvidence3
TacticDiscovery

Once deployed, ARES RAT performed automated system profiling, recursive file enumeration, and structured data exfiltration.

T1083File and Directory DiscoveryEvidence1
TacticDiscovery

Once deployed, ARES RAT performed automated system profiling, recursive file enumeration, and structured data exfiltration.

T1071Application Layer ProtocolEvidence1

"...connects to a hard-coded command-and-control (C2) server..."

T1105Ingress Tool TransferEvidence1

"...shell script downloaded from an external server."

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Once deployed, ARES RAT performed automated system profiling, recursive file enumeration, and structured data exfiltration.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.