Threat Advisory

Transparent Tribe APT Targets Linux Using Legitimate Tools and Services

Threat: Malware
Threat Actor Name: APT36
Threat Actor Type: Cyber Espionage Group
Targeted Region: India
Alias: G0134, Mythic Leopard, Temp.Lapis, Transparent Tribe, ProjectM, Copper Fieldstone, Earth Karkaddan, Green Havildar, ATK64, APT-C-56 , STEPPY-KAVACH
Threat Actor Region: Pakistan
Targeted Sector: Government & Defense, Aerospace & Aviation
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researcher has uncovered an ongoing cyber espionage campaign conducted by the advanced persistent threat group Transparent Tribe (APT36), targeting the government, defense, and aerospace sectors of India. This campaign, which has been active, is characterized by its tactics and strategic focus on critical sectors. Transparent Tribe, a Pakistan-based threat actor, is known for its persistent targeting of Indian entities, and its activities in this campaign align with geopolitical tensions between India and Pakistan.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researcher has uncovered an ongoing cyber espionage campaign conducted by the advanced persistent threat group Transparent Tribe (APT36), targeting the government, defense, and aerospace sectors of India. This campaign, which has been active, is characterized by its tactics and strategic focus on critical sectors. Transparent Tribe, a Pakistan-based threat actor, is known for its persistent targeting of Indian entities, and its activities in this campaign align with geopolitical tensions between India and Pakistan.[emaillocker id="1283"]

Transparent Tribe's campaign exhibits a significant evolution in their toolkit and attack vectors. The group has been leveraging cross-platform programming languages such as Python, Golang, and Rust, and exploiting popular web services including Telegram, Discord, Slack, and Google Drive for command-and-control (C2) operations. The threat actors have primarily used phishing emails with malicious ZIP archives or links to deliver their payloads. A notable shift in their tactics is the use of ISO images as an attack vector. Additionally, they deployed a new Golang-compiled espionage tool capable of exfiltrating files, taking screenshots, and executing commands. Transparent Tribe's tools include the GLOBSHELL exfiltration utility and various Python-based downloaders compiled into ELF binaries, reflecting their focus on Linux-based systems like MayaOS, which is being developed by the Indian defense sector.

The ongoing cyber espionage activities by Transparent Tribe highlight their persistent efforts to infiltrate and gather intelligence from India's critical sectors. The group's continued adaptation and evolution in tactics, techniques, and procedures underscore the strategic nature of their operations, likely aligned with Pakistan's interests. Despite the group's operational security measures, several indicators, such as time zone settings and network infrastructure, link them to Pakistan. This campaign is expected to persist, emphasizing the need for heightened cybersecurity measures and vigilance within the targeted sectors to mitigate the risks posed by Transparent Tribe.

THREAT PROFILE:

Tactic Technique Id Technique
Resource Development T1588 Obtain Capabilities
Initial Access T1566 Phishing
Execution T1204 User Execution
 T1053 Scheduled Task/Job
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1027 Obfuscated Files or Information
T1564 Hide Artifacts
T1140 Deobfuscate/Decode Files or Information
Discovery T1082 System Information Discovery
T1217 Browser Information Discovery
Collection T1113 Screen Capture
Command and Control T1071 Application Layer Protocol

REFERENCES:

The following reports contain further technical details:

https://www.darkreading.com/cyberattacks-data-breaches/pakistani-transparent-tribe-apt-aims-for-cross-platform-impact

[/emaillocker]
crossmenu