logo

APT36 Malware Campaign Targeting Windows LNK Files to Attack Indian Government Entities

ID: e47f7f61-65ce-526e-b9cd-f24619ad27e5

STIX ID: report--e47f7f61-65ce-526e-b9cd-f24619ad27e5

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-12-31

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

APT36 (Transparent Tribe) is running a targeted spear‑phishing campaign against Indian government and strategic entities using ZIP attachments with double‑extension `.pdf.lnk` shortcut files that invoke mshta to fetch a remote HTA. The HTA decodes Base64/XOR payloads in memory (ReadOnly/WriteOnly), weakens .NET checks, and loads an encrypted .NET RAT for remote control, surveillance, and data exfiltration; observed indicators include the mshta invocation of "https://innlive.in/.../jip.hta" and filenames such as "Online JLPT Exam Dec 2025.pdf" and "usbsyn.pim".

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.