logo

APT36 Group Attacking Windows Systems Absuing Google Drive & Slack

ID: b83dc7c6-42f9-59df-bc20-d1f352fd265f

STIX ID: report--b83dc7c6-42f9-59df-bc20-d1f352fd265f

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2024-11-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

ElizaRAT, attributed to Pakistan-linked APT36 (Transparent Tribe), is an evolving Windows RAT used in espionage campaigns against Indian government and military targets; it is delivered via phishing .CPL files and Google Storage links, uses cloud-based C2 (Slack, Google Drive, VPS), embeds .NET components and SQLite storage, and deploys secondary payloads like ApolloStealer and a USB-focused component (ConnectX) to collect and exfiltrate sensitive documents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.