logo

APT36 Hackers Used Python-Based ELF Malware to Target Indian Government Entities

ID: 09e75ffc-274d-5673-8a50-723e61c88389

STIX ID: report--09e75ffc-274d-5673-8a50-723e61c88389

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

APT36 (Transparent Tribe) is conducting a targeted campaign against Indian government agencies using spear-phishing archives that drop weaponized .desktop shortcut files which download and run a Python-based ELF remote access Trojan on Linux (BOSS OS). The malware provides remote command execution, screenshot capture, data exfiltration, and persistence via systemd; researchers identified active infrastructure (lionsdenim.xyz, IP 185.235.137.90) and recommend strengthening email security, EDR, and application authorization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.