S1028Windows
S1028Action RAT
Platforms
1
ATT&CK
14.1
References
2
Description
[Action RAT](https://attack.mitre.org/software/S1028) is a remote access tool written in Delphi that has been used by [SideCopy](https://attack.mitre.org/groups/G1008) since at least December 2021 against Indian and Afghani government personnel.(Citation: MalwareBytes SideCopy Dec 2021)
Documented platforms: Windows. Attributed to ATT&CK group: SideCopy. Catalogued in ATT&CK 14.1. 2 references curated.
Platforms· 1
Windows
Attributed to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Group | SideCopyg1008 | 100% | live |
References
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.