logo

APT36 Hackers Exploit Malicious PDF Files to Attack Indian Railways, Oil, and Government Networks

ID: daaae017-7a8d-596e-bbc2-ca6757ddf940

STIX ID: report--daaae017-7a8d-596e-bbc2-ca6757ddf940

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2025-08-01

Date Updated: 2026-04-13

Author: Priya

...
...

Pakistan-linked APT36 (Transparent Tribe) has expanded operations to target Indian critical infrastructure (railways, oil & gas, government) using malicious .desktop files disguised as PDFs to deploy the Poseidon backdoor (Mythic C2, Go) and establish persistence; researchers observed active C2 servers, localized infrastructure in India, over 100 phishing domains impersonating government entities, and published MD5 IOCs for the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.