Article Details

Scrape Timestamp (UTC): 2026-01-02 14:00:20.032

Source: https://thehackernews.com/2026/01/transparent-tribe-launches-new-rat.html

Original Article Text

Click to Toggle View

Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia. The threat actor known as Transparent Tribe has been attributed to a fresh set of attacks targeting Indian governmental, academic, and strategic entities with a remote access trojan (RAT) that grants them persistent control over compromised hosts. "The campaign employs deceptive delivery techniques, including a weaponized Windows shortcut (LNK) file masquerading as a legitimate PDF document and embedded with full PDF content to evade user suspicion," CYFIRMA said in a technical report. Transparent Tribe, also called APT36, is a hacking group that's known for mounting cyber espionage campaigns against Indian organizations. Assessed to be of Indian origin, the state-sponsored adversary has been active since at least 2013. The threat actor boasts of an ever-evolving arsenal of RATs to realize its goals. Some of the trojans put to use by Transparent Tribe in recent years include CapraRAT, Crimson RAT, ElizaRAT, and DeskRAT. The latest set of attacks began with a spear-phishing email containing a ZIP archive with a LNK file disguised as a PDF. Opening the file triggers the execution of a remote HTML Application (HTA) script using "mshta.exe" that decrypts and loads the final RAT payload directly in memory. In tandem, the HTA downloads and opens a decoy PDF document so as not to arouse users' suspicion. "After decoding logic is established, the HTA leverages ActiveX objects, particularly WScript.Shell, to interact with the Windows environment," CYFIRMA noted. "This behavior demonstrates environment profiling and runtime manipulation, ensuring compatibility with the target system and increasing execution reliability techniques commonly observed in malware abusing 'mshta.exe.'" A noteworthy aspect of the malware is its ability to adapt its persistence method based on the antivirus solutions installed on the infected machine - The second HTA file includes a DLL named "iinneldc.dll" that functions as a fully-featured RAT, supporting remote system control, file management, data exfiltration, screenshot capture, clipboard manipulation, and process control. "APT36 (Transparent Tribe) remains a highly persistent and strategically driven cyber-espionage threat, with a sustained focus on intelligence collection targeting Indian government entities, educational institutions, and other strategically relevant sectors," the cybersecurity company said. In recent weeks, APT36 has also been linked to another campaign that leverages a malicious shortcut file disguised as a government advisory PDF ("NCERT-Whatsapp-Advisory.pdf.lnk") to deliver a .NET-based loader, which then drops additional executables and malicious DLLs to establish remote command execution, system reconnaissance, and long-term access. The shortcut is designed to execute an obfuscated command using cmd.exe to retrieve an MSI installer ("nikmights.msi") from a remote server ("aeroclubofindia.co[.]in"), which is responsible for initiating a series of actions - It's worth pointing out that the lure PDF displayed is a legitimate advisory issued by the National Cyber Emergency Response Team of Pakistan (PKCERT) in 2024 about a fraudulent WhatsApp message campaign targeting government entities in Pakistan with a malicious WinRAR file that infects systems with malware. The DLL "wininet.dll" connects to a hard-coded command-and-control (C2) infrastructure hosted at dns.wmiprovider[.]com. It was registered in mid-April 2025. The C2 associated with the activity is currently inactive, but the Windows Registry-based persistence ensures that the threat can be resurrected at any time in the future. "The DLL implements multiple HTTP GET–based endpoints to establish communication with the C2 server, perform updates, and retrieve attacker-issued commands," CYFIRMA said. "To evade static string detection, the endpoint characters are intentionally stored in reversed order." The list of endpoints is as follows - The DLL also queries installed antivirus products on the victim system, turning it into a potent tool capable of conducting reconnaissance and gathering sensitive information. Patchwork Linked to New StreamSpy Trojan The disclosure comes weeks after Patchwork (aka Dropping Elephant or Maha Grass), a hacking group believed to be of Indian origin, was linked to attacks targeting Pakistan's defense sector with a Python-based backdoor that's distributed via phishing emails containing ZIP files, according to security researcher Idan Tarab. Present within the archive is an MSBuild project that, when executed via "msbuild.exe," deploys a dropper to ultimately install and launch the Python RAT. The malware is equipped to contact a C2 server and run remote Python modules, execute commands, and upload/download files. "This campaign represents a modernized, highly obfuscated Patchwork APT toolkit blending MSBuild LOLBin loaders, PyInstaller‑modified Python runtimes, marshalled bytecode implants, geofencing, randomized PHP C2 endpoints, [and] realistic persistence mechanisms," Tarab said. As of December 2025, Patchwork has also been associated with a previously undocumented trojan named StreamSpy, which uses WebSocket and HTTP protocols for C2 communication. While the WebSocket channel is used to receive instructions and transmit the execution results, HTTP is leveraged for file transfers. StreamSpy's links to Patchwork, per QiAnXin, stem from its similarities to Spyder, a variant of another backdoor named WarHawk that's attributed to SideWinder. Patchwork's use of Spider dates all the way back to 2023. Distributed via ZIP archives ("OPS-VII-SIR.zip") hosted on "firebasescloudemail[.]com," the malware ("Annexure.exe") can harvest system information, establish persistence via Windows Registry, scheduled task, or via a LNK file in the Startup folder, communicate with the C2 server using HTTP and WebSocket. The list of support commands is below - QinAnXin said the StreamSpy download site also hosts Spyder variants with extensive data collection features, adding the malware's digital signature exhibits correlations with a different Windows RAT called ShadowAgent attributed to the DoNot Team (aka Brainworm). Interestingly, 360 Threat Intelligence Center flagged the same "Annexure.exe" executable as ShadowAgent in November 2025. "The emergence of the StreamSpy Trojan and Spyder variants from the Maha Grass group indicates that the group is continuously iterating its arsenal of attack tools," the Chinese security vendor said. "In the StreamSpy trojan, attackers attempt to use WebSocket channels for command issuance and result feedback to evade detection and censorship of HTTP traffic. Additionally, the correlated samples further confirm that the Maha Grass and DoNot attack groups have some connections in terms of resource sharing."

Daily Brief Summary

NATION STATE ACTIVITY // Transparent Tribe Launches New RAT Attacks on Indian Entities

Transparent Tribe, also known as APT36, has initiated a new cyber espionage campaign targeting Indian government and academic sectors using a sophisticated remote access trojan (RAT).

The group employs spear-phishing tactics, delivering a malicious LNK file disguised as a PDF, which executes a remote HTML Application to load the RAT payload.

This campaign demonstrates advanced evasion techniques, including environment profiling and runtime manipulation, to ensure compatibility and reliability across targeted systems.

The malware adapts its persistence methods based on installed antivirus solutions, enhancing its ability to maintain long-term access and control.

APT36's attacks leverage multiple RATs, such as CapraRAT and Crimson RAT, for comprehensive system control, data exfiltration, and reconnaissance.

The campaign's infrastructure includes a command-and-control server that, although currently inactive, can be reactivated, posing ongoing risks to compromised entities.

These activities underscore the persistent threat posed by state-sponsored actors to national security and critical sectors, necessitating enhanced defensive measures and threat intelligence sharing.