Indian Governmental Organizations Targeted by APT-36
ID: 244b8dbb-4708-5856-aa42-ecbb09eaa9cd
STIX ID: report--244b8dbb-4708-5856-aa42-ecbb09eaa9cd
Feed Name: Zscaler Security Research Blog
Threat Score
APT-36 (Transparent Tribe) conducted targeted campaigns against Indian government users in 2022 by abusing Google Ads and third-party app stores to deliver backdoored Kavach MFA installers, deploy credential-phishing portals, and operate a new Python-based data exfiltration stealer called LimePad; the report provides technical analysis, persistence and network behaviors, and a comprehensive set of IoCs and detection notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
