Cloudy With a Chance of RATs: Unveiling APT36 and the Evolution of ElizaRAT
ID: 82e80235-d10a-57f5-a824-7684925c0b93
STIX ID: report--82e80235-d10a-57f5-a824-7684925c0b93
Feed Name: Check Point Research
Check Point Research documents APT36 (Transparent Tribe) use of a modular Windows RAT named ElizaRAT and new stealer payloads (ApoloStealer, ConnectX) in 2023–2024 campaigns targeting Indian government and military-related entities. The report details infection vectors (CPL droppers distributed via Google Drive/spearphishing), persistent mechanisms (scheduled tasks, LNK shortcuts), cloud-based C2 abuse (Slack, Google Cloud Storage, Telegram), payload behaviors (file and USB stealing, SQLite-based staging, time-zone checks), and includes comprehensive IOCs (MD5/SHA hashes and C2 IP addresses) to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
