logo

TransparentTribe targets Indian military organisations with DeskRAT

ID: 05b7f498-f459-50c0-b7ac-d34295c07970

STIX ID: report--05b7f498-f459-50c0-b7ac-d34295c07970

Feed Name: Sekoia.io Blog

Threat Score
88/100

Date Published: 2025-10-23

Date Updated: 2026-04-29

Author: Amaury G., Coline Chavane and Sekoia TDR

...
...

Sekoia.io TDR describes an active TransparentTribe (APT36) phishing campaign (June–Sept 2025) targeting Indian government/defense Linux systems (BOSS). Attackers delivered a multi-stage chain via ZIP archives containing a malicious DESKTOP dropper that downloads and executes a Golang RAT called DeskRAT; the RAT uses insecure WebSocket C2 (stealth servers), supports file collection/exfiltration, remote execution, and multiple Linux persistence techniques. The report includes technical indicators, C2 details, decoy documents, and detection/hunting artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.