logo

Espionage Without Noise: Understanding APT36’s Enduring Campaigns

ID: 32b75756-0ffe-5bb8-a745-5201e9bfd616

STIX ID: report--32b75756-0ffe-5bb8-a745-5201e9bfd616

Feed Name: Aryaka

Threat Score
88/100

Date Published: 2026-02-10

Date Updated: 2026-04-27

Author: Aditya K Sood

...
...

**Executive Summary:** Aryaka Threat Research Labs observed multiple active espionage campaigns by Transparent Tribe (APT36) and affiliated SideCopy targeting Indian defense and government organizations, deploying GETA RAT on Windows (via LNK/HTA, mshta abuse, XAML deserialization and in-memory execution), ARES RAT on Linux (Go-based downloader, systemd user service persistence, automated profiling and exfiltration), and an emerging Desk RAT delivered via a malicious PowerPoint Add-In; these cross-platform, stealthy and persistent tools emphasize long-term intelligence collection and the need for cross-platform visibility and behavioral detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.