APT36 Hackers Used Python-Based ELF Malware to Target Indian Government Entities
ID: 09e75ffc-274d-5673-8a50-723e61c88389
STIX ID: report--09e75ffc-274d-5673-8a50-723e61c88389
Feed Name: cybersecurityNews.com
APT36 (Transparent Tribe) is conducting a targeted campaign against Indian government agencies using spear-phishing archives that drop weaponized .desktop shortcut files which download and run a Python-based ELF remote access Trojan on Linux (BOSS OS). The malware provides remote command execution, screenshot capture, data exfiltration, and persistence via systemd; researchers identified active infrastructure (lionsdenim.xyz, IP 185.235.137.90) and recommend strengthening email security, EDR, and application authorization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
