EXECUTIVE SUMMARY
Researcher has uncovered an ongoing cyber espionage campaign conducted by the advanced persistent threat group Transparent Tribe (APT36), targeting the government, defense, and aerospace sectors of India. This campaign, which has been active, is characterized by its tactics and strategic focus on critical sectors. Transparent Tribe, a Pakistan-based threat actor, is known for its persistent targeting of Indian entities, and its activities in this campaign align with geopolitical tensions between India and Pakistan.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Researcher has uncovered an ongoing cyber espionage campaign conducted by the advanced persistent threat group Transparent Tribe (APT36), targeting the government, defense, and aerospace sectors of India. This campaign, which has been active, is characterized by its tactics and strategic focus on critical sectors. Transparent Tribe, a Pakistan-based threat actor, is known for its persistent targeting of Indian entities, and its activities in this campaign align with geopolitical tensions between India and Pakistan.[emaillocker id="1283"]
Transparent Tribe's campaign exhibits a significant evolution in their toolkit and attack vectors. The group has been leveraging cross-platform programming languages such as Python, Golang, and Rust, and exploiting popular web services including Telegram, Discord, Slack, and Google Drive for command-and-control (C2) operations. The threat actors have primarily used phishing emails with malicious ZIP archives or links to deliver their payloads. A notable shift in their tactics is the use of ISO images as an attack vector. Additionally, they deployed a new Golang-compiled espionage tool capable of exfiltrating files, taking screenshots, and executing commands. Transparent Tribe's tools include the GLOBSHELL exfiltration utility and various Python-based downloaders compiled into ELF binaries, reflecting their focus on Linux-based systems like MayaOS, which is being developed by the Indian defense sector.
The ongoing cyber espionage activities by Transparent Tribe highlight their persistent efforts to infiltrate and gather intelligence from India's critical sectors. The group's continued adaptation and evolution in tactics, techniques, and procedures underscore the strategic nature of their operations, likely aligned with Pakistan's interests. Despite the group's operational security measures, several indicators, such as time zone settings and network infrastructure, link them to Pakistan. This campaign is expected to persist, emphasizing the need for heightened cybersecurity measures and vigilance within the targeted sectors to mitigate the risks posed by Transparent Tribe.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Resource Development | T1588 | Obtain Capabilities |
| Initial Access | T1566 | Phishing |
| Execution | T1204 | User Execution |
| T1053 | Scheduled Task/Job | |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1564 | Hide Artifacts | |
| T1140 | Deobfuscate/Decode Files or Information | |
| Discovery | T1082 | System Information Discovery |
| T1217 | Browser Information Discovery | |
| Collection | T1113 | Screen Capture |
| Command and Control | T1071 | Application Layer Protocol |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]