APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities
ID: 3190a47b-0f14-5b5c-929f-30a2b7987584
STIX ID: report--3190a47b-0f14-5b5c-929f-30a2b7987584
Feed Name: The Hacker News
Threat Score
Indian defense and government-aligned organizations have been targeted by multiple espionage campaigns attributed to SideCopy and APT36 (Transparent Tribe) that deploy cross-platform remote access trojans—Geta RAT, Ares RAT, and DeskRAT—via phishing with malicious LNK/HTA files, PowerPoint Add-Ins, and Golang/Python loaders; the malware enables reconnaissance, credential and data theft, command execution, and long-term persistence across Windows and Linux hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
