APT36 Targets Indian Government Systems Using Malicious Windows LNK Files
ID: 6f5a0aad-3f62-52d9-b875-2edab4d4efa4
STIX ID: report--6f5a0aad-3f62-52d9-b875-2edab4d4efa4
Feed Name: Cyber Press
CYFIRMA researchers reported an APT36 (Transparent Tribe) espionage campaign that uses spear-phishing ZIPs containing deceptive “.pdf.lnk” shortcuts embedding full PDFs; the LNK launches mshta.exe to fetch an HTA loader which runs encrypted payloads in memory, deploying DLLs (ki2mtmkl.dll, iinneldc.dll) that act as a fileless RAT. The malware provides remote control, screenshot/clipboard/file theft, environment-aware persistence that alters behavior based on detected antivirus products, and communicates with C2 infrastructure including domains (innlive.in, drjagrutichavan.com) and IP 2.56.10.86 over TCP 8621; defenders are advised to block LNK attachments, restrict mshta.exe, and monitor the listed indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
