Transparent Tribe Hacker Group Targets India’s Startup Ecosystem in Cyber Attack
ID: ee3e6dd4-15a6-510e-b3df-eb5533871e90
STIX ID: report--ee3e6dd4-15a6-510e-b3df-eb5533871e90
Feed Name: GBHackers
Transparent Tribe (APT36) has shifted tactics to target Indian startups—particularly those in OSINT and cybersecurity—using spear-phishing emails carrying ISO attachments that contain a malicious LNK shortcut. When opened, the LNK executes a hidden batch script, shows a decoy document, and installs the Crimson RAT (a large, packed Remote Access Trojan used for surveillance, data theft, and remote control). Acronis links the campaign to Transparent Tribe via reused code, U.S.-hosted infrastructure, and repeated filename misspellings; the attackers are employing a supply-chain-style approach to access government-linked data through trusted private vendors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
