TransparentTribe Targets Indian Military with DeskRAT Malware
ID: b4d69dc4-2a12-5419-ac13-f84272ca7ac0
STIX ID: report--b4d69dc4-2a12-5419-ac13-f84272ca7ac0
Feed Name: Sekoia.com
This report details a TransparentTribe (APT36) phishing campaign from mid‑2025 that uses ZIP attachments containing a crafted DESKTOP dropper to fetch and execute a multi‑stage payload culminating in a Go‑based RAT named DeskRAT; the malware establishes insecure WebSocket C2 connections to staging/stealth servers, implements multiple Linux persistence techniques, exfiltrates files, and uses decoy PDFs tied to local events to lure Indian government and defense targets (BOSS distributions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
