logo

APT36 Targets Linux Systems With New Tools Designed to Disrupt Services

ID: 36a72721-74d6-5ae2-93cd-1c35717a54df

STIX ID: report--36a72721-74d6-5ae2-93cd-1c35717a54df

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-02-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Active APT espionage campaigns:** Recent observations link Transparent Tribe (APT36) and SideCopy to coordinated, cross‑platform campaigns against Indian government and defense targets using Windows and Linux RATs (GETA, ARES, Desk RAT) delivered via phishing (LNK/HTA), Go-based downloaders, and malicious PowerPoint add-ins, employing persistence (startup mechanisms, systemd services), evasion (mshta.exe, XAML deserialization, memory-resident techniques), and WebSocket C2 for prolonged intelligence collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.