Transparent Tribe Hacker Group Attacking India’s Startup Ecosystem
ID: 9942600e-a178-56f9-87d4-bb017441ad25
STIX ID: report--9942600e-a178-56f9-87d4-bb017441ad25
Feed Name: cybersecurityNews.com
Transparent Tribe (APT36) has shifted focus to India’s startup ecosystem—especially cybersecurity/intelligence firms—deploying Crimson RAT via ISO attachments (e.g., MeetBisht.iso) that contain a malicious shortcut, decoy document, batch script, and PowerShell chain which installs a hard-linked executable and evades detection through file bloating and randomized code; the malware communicates with hardcoded C2 servers on non-standard ports and can monitor screens, record audio, and exfiltrate files. Recommended mitigations include blocking ISO/container attachments, security awareness training, endpoint detection for suspicious PowerShell and file activity, and network monitoring for unusual outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
