APT36 Targets Linux Systems With New Tools Designed to Disrupt Services
ID: 36a72721-74d6-5ae2-93cd-1c35717a54df
STIX ID: report--36a72721-74d6-5ae2-93cd-1c35717a54df
Feed Name: GBHackers
**Active APT espionage campaigns:** Recent observations link Transparent Tribe (APT36) and SideCopy to coordinated, cross‑platform campaigns against Indian government and defense targets using Windows and Linux RATs (GETA, ARES, Desk RAT) delivered via phishing (LNK/HTA), Go-based downloaders, and malicious PowerPoint add-ins, employing persistence (startup mechanisms, systemd services), evasion (mshta.exe, XAML deserialization, memory-resident techniques), and WebSocket C2 for prolonged intelligence collection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
