logo

Cloudy With a Chance of RATs: Unveiling APT36 and the Evolution of ElizaRAT

ID: 82e80235-d10a-57f5-a824-7684925c0b93

STIX ID: report--82e80235-d10a-57f5-a824-7684925c0b93

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2024-11-04

Date Updated: 2026-04-27

Author: stcpresearch

...
...

Check Point Research documents APT36 (Transparent Tribe) use of a modular Windows RAT named ElizaRAT and new stealer payloads (ApoloStealer, ConnectX) in 2023–2024 campaigns targeting Indian government and military-related entities. The report details infection vectors (CPL droppers distributed via Google Drive/spearphishing), persistent mechanisms (scheduled tasks, LNK shortcuts), cloud-based C2 abuse (Slack, Google Cloud Storage, Telegram), payload behaviors (file and USB stealing, SQLite-based staging, time-zone checks), and includes comprehensive IOCs (MD5/SHA hashes and C2 IP addresses) to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.