logo

APT36's Updated Arsenal

ID: f651488b-79c4-5d0a-b26a-5a750a53b9df

STIX ID: report--f651488b-79c4-5d0a-b26a-5a750a53b9df

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

This report documents a low-volume but active APT36 campaign (May–Aug 2023) leveraging malicious Linux .desktop files distributed in ZIP archives to deliver cross-platform Linux payloads (Mythic Poseidon binaries) and decoy PDFs to Indian government targets; the files perform background downloads, set execution permissions, establish persistence via cron, and connect to identified C2 servers. The report includes sample metadata (MD5 hashes, filenames), attacker infrastructure (domains and IPs), decoded command lines, and analysis of an inflated-file evasion technique used to bypass scanners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.