APT36 Refines Tools in Attacks on Indian Targets
ID: 7e0a5589-24a8-5856-981f-e6d8e939e7cc
STIX ID: report--7e0a5589-24a8-5856-981f-e6d8e939e7cc
Feed Name: Dark Reading
Check Point Research observed Pakistan-linked APT36 (aka Transparent Tribe) deploying upgraded ElizaRAT variants alongside new payloads—ApoloStealer and ConnectX—across at least three campaigns targeting Indian government, military, and diplomatic entities; the actor uses CPL droppers, living-off-the-land binaries, and legitimate cloud/messaging services (Google Drive, Slack, Telegram) for C2, enabling modular, stepwise espionage and cross-platform compromise (Windows, Android, Linux).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
