APT36 Group Attacking Windows Systems Absuing Google Drive & Slack
ID: b83dc7c6-42f9-59df-bc20-d1f352fd265f
STIX ID: report--b83dc7c6-42f9-59df-bc20-d1f352fd265f
Feed Name: cybersecurityNews.com
Threat Score
ElizaRAT, attributed to Pakistan-linked APT36 (Transparent Tribe), is an evolving Windows RAT used in espionage campaigns against Indian government and military targets; it is delivered via phishing .CPL files and Google Storage links, uses cloud-based C2 (Slack, Google Drive, VPS), embeds .NET components and SQLite storage, and deploys secondary payloads like ApolloStealer and a USB-focused component (ConnectX) to collect and exfiltrate sensitive documents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
