logo

APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities

ID: 3190a47b-0f14-5b5c-929f-30a2b7987584

STIX ID: report--3190a47b-0f14-5b5c-929f-30a2b7987584

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Indian defense and government-aligned organizations have been targeted by multiple espionage campaigns attributed to SideCopy and APT36 (Transparent Tribe) that deploy cross-platform remote access trojans—Geta RAT, Ares RAT, and DeskRAT—via phishing with malicious LNK/HTA files, PowerPoint Add-Ins, and Golang/Python loaders; the malware enables reconnaissance, credential and data theft, command execution, and long-term persistence across Windows and Linux hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.