logo

Covert Data Heist: APT36 Exploits ZIP Vulnerabilities in BOSS Linux Systems

ID: 1c9e7331-c58c-529b-83f9-95b4d47a2d1f

STIX ID: report--1c9e7331-c58c-529b-83f9-95b4d47a2d1f

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2025-07-07

Date Updated: 2026-04-19

Author: Mandvi

...
...

CYFIRMA identifies a sophisticated APT36 campaign targeting India’s defense sector by leveraging phishing ZIP attachments that drop a .desktop launcher which silently installs a Go-based ELF backdoor (BOSS.elf) on BOSS Linux systems; the malware performs system reconnaissance, captures screenshots, maintains persistent TCP C2 (notably 101.99.92.182:12520), and facilitates covert data exfiltration, with multiple IOCs and mitigation recommendations provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.