logo

APT36 Targets Indian Infrastructure with Desktop Lures and Poseidon Backdoor

ID: 989420e9-bfb2-57aa-babc-e1c4f46e61bd

STIX ID: report--989420e9-bfb2-57aa-babc-e1c4f46e61bd

Feed Name: Hunt.io Blog

Threat Score
85/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

APT36 (Transparent Tribe) is actively targeting Indian government and civilian infrastructure using .desktop file lures to deliver a Go-based Poseidon backdoor built on the Mythic C2 framework and a broad phishing infrastructure; analysts identified two infection variants (single and redundant C2), live Mythic C2 servers (port 7443) and multiple DigitalOcean-hosted C2 IPs, plus over 100 phishing domains (many hosted via AlexHost/AlexHost-linked IPs) impersonating Indian government services, and the report provides hashes, IPs, domain lists and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.