New year, new sector: Transparent Tribe targets India’s startup ecosystem
ID: 8c5e71e8-b150-5d7a-828b-365c509fcb19
STIX ID: report--8c5e71e8-b150-5d7a-828b-365c509fcb19
Feed Name: TRU Security by Acronis
Acronis TRU reports that Transparent Tribe (APT36) has broadened its targeting to include Indian startups—especially OSINT and cybersecurity firms—using spear-phishing with ISO container files and malicious LNK/batch runners to deploy Crimson RAT. The report provides technical analysis of the RAT (capabilities such as screen/webcam/audio capture, file transfer, process control), obfuscation and C2 behavior, execution chain, infrastructure artifacts (e.g., 93.127.133.9, sharmaxme11.org), IoCs (sample hashes and filenames), and attribution evidence linking the activity to APT36.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
