logo

Advisory: Pahalgam Attack themed decoys used by APT36 to target the Indian Government

ID: 05803a00-0464-5448-95bd-d755f26f5fbd

STIX ID: report--05803a00-0464-5448-95bd-d755f26f5fbd

Feed Name: Seqrite Blog

Threat Score
88/100

Date Published: 2025-04-30

Date Updated: 2026-04-30

Author: Rhishav Kanjilal

...
...

Seqrite Labs discovered a targeted campaign by APT36 (Transparent Tribe) leveraging Pahalgam terror-attack themed phishing PDFs and a malicious PPAM add-on to impersonate Indian government domains and deploy Crimson RAT; the report includes domain registrations, URLs, file hashes, C2 IPs, detailed RAT capabilities, MITRE ATT&CK mappings, and recommended mitigations such as disabling macros, email/document scanning, network segmentation, and threat-intel integration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.