logo

APT36 Refines Tools in Attacks on Indian Targets

ID: 7e0a5589-24a8-5856-981f-e6d8e939e7cc

STIX ID: report--7e0a5589-24a8-5856-981f-e6d8e939e7cc

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-11-04

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Check Point Research observed Pakistan-linked APT36 (aka Transparent Tribe) deploying upgraded ElizaRAT variants alongside new payloads—ApoloStealer and ConnectX—across at least three campaigns targeting Indian government, military, and diplomatic entities; the actor uses CPL droppers, living-off-the-land binaries, and legitimate cloud/messaging services (Google Drive, Slack, Telegram) for C2, enabling modular, stepwise espionage and cross-platform compromise (Windows, Android, Linux).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.