logo

TransparentTribe Targets Indian Military with DeskRAT Malware

ID: b4d69dc4-2a12-5419-ac13-f84272ca7ac0

STIX ID: report--b4d69dc4-2a12-5419-ac13-f84272ca7ac0

Feed Name: Sekoia.com

Threat Score
90/100

Date Published: 2025-10-23

Date Updated: 2026-07-20

...
...

This report details a TransparentTribe (APT36) phishing campaign from mid‑2025 that uses ZIP attachments containing a crafted DESKTOP dropper to fetch and execute a multi‑stage payload culminating in a Go‑based RAT named DeskRAT; the malware establishes insecure WebSocket C2 connections to staging/stealth servers, implements multiple Linux persistence techniques, exfiltrates files, and uses decoy PDFs tied to local events to lure Indian government and defense targets (BOSS distributions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.