APT36's Updated Arsenal
ID: f651488b-79c4-5d0a-b26a-5a750a53b9df
STIX ID: report--f651488b-79c4-5d0a-b26a-5a750a53b9df
Feed Name: Zscaler Security Research Blog
This report documents a low-volume but active APT36 campaign (May–Aug 2023) leveraging malicious Linux .desktop files distributed in ZIP archives to deliver cross-platform Linux payloads (Mythic Poseidon binaries) and decoy PDFs to Indian government targets; the files perform background downloads, set execution permissions, establish persistence via cron, and connect to identified C2 servers. The report includes sample metadata (MD5 hashes, filenames), attacker infrastructure (domains and IPs), decoded command lines, and analysis of an inflated-file evasion technique used to bypass scanners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
