logo

APT36 Targets Indian Government Systems Using Malicious Windows LNK Files

ID: 6f5a0aad-3f62-52d9-b875-2edab4d4efa4

STIX ID: report--6f5a0aad-3f62-52d9-b875-2edab4d4efa4

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2025-12-31

Date Updated: 2026-04-19

Author: Priya

...
...

CYFIRMA researchers reported an APT36 (Transparent Tribe) espionage campaign that uses spear-phishing ZIPs containing deceptive “.pdf.lnk” shortcuts embedding full PDFs; the LNK launches mshta.exe to fetch an HTA loader which runs encrypted payloads in memory, deploying DLLs (ki2mtmkl.dll, iinneldc.dll) that act as a fileless RAT. The malware provides remote control, screenshot/clipboard/file theft, environment-aware persistence that alters behavior based on detected antivirus products, and communicates with C2 infrastructure including domains (innlive.in, drjagrutichavan.com) and IP 2.56.10.86 over TCP 8621; defenders are advised to block LNK attachments, restrict mshta.exe, and monitor the listed indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.