APT36 Malware Campaign Targeting Windows LNK Files to Attack Indian Government Entities
ID: e47f7f61-65ce-526e-b9cd-f24619ad27e5
STIX ID: report--e47f7f61-65ce-526e-b9cd-f24619ad27e5
Feed Name: cybersecurityNews.com
APT36 (Transparent Tribe) is running a targeted spear‑phishing campaign against Indian government and strategic entities using ZIP attachments with double‑extension `.pdf.lnk` shortcut files that invoke mshta to fetch a remote HTA. The HTA decodes Base64/XOR payloads in memory (ReadOnly/WriteOnly), weakens .NET checks, and loads an encrypted .NET RAT for remote control, surveillance, and data exfiltration; observed indicators include the mshta invocation of "https://innlive.in/.../jip.hta" and filenames such as "Online JLPT Exam Dec 2025.pdf" and "usbsyn.pim".
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
