Pakistani APTs Escalate Attacks on Indian Gov. Seqrite Labs Unveils Threats and Connections
ID: f07ad180-7726-5e94-b36e-538833f2b426
STIX ID: report--f07ad180-7726-5e94-b36e-538833f2b426
Feed Name: Seqrite Blog
Seqrite Labs documents multiple active campaigns (Mar–Apr 2024) by Pakistan-linked APTs SideCopy and Transparent Tribe (APT36) targeting Indian government/defense entities: SideCopy deploys Delphi AllaKore RAT (dual instances) via LNK→MSHTA→HTA chains using compromised domains and Contabo-hosted C2s, while APT36 continues using .NET Crimson RAT variants (including obfuscated/packed builds) via maldocs (XLAM) with base64-embedded payloads; the report provides infection-chain analysis, functionality (recon, keylogging, file ops, exfiltration), extensive IOCs (hashes, domains, IPs, URLs, file paths), infrastructure correlation between groups, and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
