Pakistan-linked hackers target Indian government, universities in new spying campaign
ID: 0d73d030-33db-5d72-a30b-6417d61595f1
STIX ID: report--0d73d030-33db-5d72-a30b-6417d61595f1
Feed Name: The Record from Recorded Future News
A Pakistan-aligned APT36 (Transparent Tribe) campaign uses spear-phishing ZIPs with a malicious file disguised as a PDF to deploy multi-stage malware 'ReadOnly' and 'WriteOnly' against Indian government, academic and strategic targets; the malware provides persistent remote access, data exfiltration, screenshotting and clipboard monitoring (including potential cryptocurrency hijacking), and demonstrates evolved TTPs such as abuse of trusted Windows components and fileless execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
