#APT36
Discover how #TransparentTribe (#APT36) uses a disguised DESKTOP dropper to deploy #DeskRAT, a Golang RAT, on BOSS Linux endpoints in India.

Our Sekoia #TDR report breaks down the full infection chain and stealthy WebSocket C2 communications .

Read more 👉 blog.sekoia.io/transparentt...
October 23, 2025 at 7:49 AM
APT36: Sicherheitsvorfall #Einbruch #Spionage #infosec #TeamInfoSec #cyberangriff
APT36: Sicherheitsvorfall
Hacker nutzen Infrastruktur anderer Hacker-Gruppe für Spionage.
www.security-incidents.de
December 9, 2024 at 6:00 PM
APT36、インド政府機関が使うBOSS Linuxシステムを攻撃 | Codebook|Security News

APT36、インド政府機関が使うBOSS Linuxシステムを攻撃|IconAdsがアプリを使い、大量のインタースティシャル広告をAndroid端末で表示|DoNot APT、ヨーロッパ ...
codebook.machinarecord.com/threatreport...
APT36、インド政府機関が使うBOSS Linuxシステムを攻撃 | Codebook|Security News
APT36、インド政府機関が使うBOSS Linuxシステムを攻撃|IconAdsがアプリを使い、大量のインタースティシャル広告をAndroid端末で表示|DoNot APT、ヨーロッパ某国の外務省をLoptikModで攻撃
codebook.machinarecord.com
July 11, 2025 at 9:50 PM
ClickFix Malware Campaign Now Hits Linux ClickFix Malware Campaign Now Hits Linux Post Views: 173 Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos. Reading Time: 3 Minutes APT36 Launches Cross-Platform ClickFix Attacks, Now T...

| Details | Interest | Feed |
Origin
www.blackhatethicalhacking.com
May 27, 2025 at 6:52 AM
APT36 attacca sistemi BOSS Linux con file autostart .desktop armati, secondo CYFIRMA, mirando a spionaggio governativo e infrastrutture critiche in India.

#apt36 #BOSSLinux #cyberspionaggio #ELF #evidenza #india #pakistan #payload #phishing #TransparentTribe
www.matricedigitale.it/2025/08/25/a...
August 25, 2025 at 1:37 PM
APT36 Returns: A New Era of Linux-Based Cyberattacks Against Indian Government Systems

Pakistan-linked APT36 is back in the cyber-espionage spotlight, launching a sophisticated campaign against Indian government entities by exploiting Linux systems. Using phishing emails disguised as procurement…
APT36 Returns: A New Era of Linux-Based Cyberattacks Against Indian Government Systems
Pakistan-linked APT36 is back in the cyber-espionage spotlight, launching a sophisticated campaign against Indian government entities by exploiting Linux systems. Using phishing emails disguised as procurement notices, attackers deliver malicious .desktop files that fetch droppers from Google Drive while displaying decoy PDFs. These attacks demonstrate an evolution in APT36’s tactics, targeting native Linux environments, executing anti-debugging measures, establishing persistent access, and communicating stealthily with command-and-control servers. This escalation highlights the growing complexity of nation-state cyber operations, showing that government agencies must now defend multi-platform infrastructures against highly customised malware campaigns.
www.cyberly.org
September 17, 2025 at 11:02 AM
Notícia da BleepingComputer

"APT36 hackers abuse Linux .desktop files to install malware" #bolhasec
APT36 hackers abuse Linux .desktop files to install malware in new attacks
The Pakistani APT36 cyberspies are using Linux .desktop files to load malware in new attacks against government and defense entities in India.
www.bleepingcomputer.com
October 8, 2025 at 9:30 PM
Blind Eagle (APT-C-36) is back, targeting gov & financial institutions in Latin America.

➡️ Phishing + WebDAV
➡️ NTLM hash theft
➡️ 65MB+ data exfil
➡️ Dynamic DNS C2 ops

Paxion Cyber stops full-chain attacks.
#CyberSecurity #APT36 #PaxionCyber #Phishing #CyberTip #Friday
June 27, 2025 at 12:23 PM
APT36 Malware Campaign Using Desktop Entry Files and Google Drive Payload Delivery otx.alienvault.com/pulse/68a78a...
August 22, 2025 at 11:38 AM
APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
October 24, 2025 at 6:59 PM
Analyzing APT36’s ElizaRAT: Evolution of Espionage Techniques
Analyzing APT36’s ElizaRAT: Evolution of Espionage Techniques
www.reco.ai
November 28, 2024 at 11:09 AM
ClickFix Malware Campaign Now Hits Linux ClickFix Malware Campaign Now Hits Linux Post Views: 181 Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos. Reading Time: 3 Minutes APT36 Launches Cross-Platform ClickFix Attacks, Now T...

| Details | Interest | Feed |
Origin
www.blackhatethicalhacking.com
May 30, 2025 at 3:32 PM
-Possible Earth Lumia campaign hacks 25 Vietnamese universities
-Goffee's new Sauropsida Linux rootkit
-APT36 targets Linux users
-Clickjacking attack on password managers
-New AI image scaling attack
-MITRE updates CWE MIHW list
-New GApps script to search for DPRK IT workers
-BSI Email Checker
August 25, 2025 at 7:25 AM
APT36 Targets Indian Government with Linux BOSS Malware via .desktop Files Cybersecurity researchers uncover a new Transparent Tribe (APT36) phishing campaign that uses weaponized Linux .desktop files disguised as… Continue reading on Medium »

Interest | Match | Feed
Origin
medium.com
August 26, 2025 at 4:28 PM
ClickFix Malware Campaign Now Hits Linux ClickFix Malware Campaign Now Hits Linux Post Views: 188 Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos. Reading Time: 3 Minutes APT36 Launches Cross-Platform ClickFix Attacks, Now T...

| Details | Interest | Feed |
Origin
www.blackhatethicalhacking.com
June 2, 2025 at 2:47 PM
ClickFix Malware Campaign Now Hits Linux ClickFix Malware Campaign Now Hits Linux Post Views: 177 Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos. Reading Time: 3 Minutes APT36 Launches Cross-Platform ClickFix Attacks, Now T...

| Details | Interest | Feed |
Origin
www.blackhatethicalhacking.com
May 29, 2025 at 9:45 AM
ClickFix Malware Campaign Now Hits Linux ClickFix Malware Campaign Now Hits Linux Post Views: 198 Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos. Reading Time: 3 Minutes APT36 Launches Cross-Platform ClickFix Attacks, Now T...

Interest | Match | Feed
Origin
www.blackhatethicalhacking.com
June 5, 2025 at 8:00 PM
📌 APT36 Enhances Stealth Tactics with Fake PDFs to Target Indian Critical Infrastructure https://www.cyberhub.blog/article/10990-apt36-enhances-stealth-tactics-with-fake-pdfs-to-target-indian-critical-infrastructure
APT36 Enhances Stealth Tactics with Fake PDFs to Target Indian Critical Infrastructure
APT36, a known cyber espionage group, has been refining its techniques to infiltrate critical infrastructure systems in India. The group is using files disguised as PDFs but are actually .desktop files, which are executable in Linux environments. This method allows APT36 to compromise strategic systems by deceiving users about the true nature of the files. The technical implications of this attack are significant. .desktop files can be configured to execute scripts or commands when opened, which means that once a user opens what they believe to be a PDF, the .desktop file can run malicious code, potentially giving the attacker access to the system. This technique highlights the need for better user education and more robust file inspection mechanisms, as it demonstrates how threat actors are continually adapting their tactics to bypass traditional security measures. The impact on the cybersecurity landscape is considerable. Critical infrastructure is a high-value target, and a sustained campaign by a group like APT36 could have severe consequences for national security, economic stability, and public safety. This attack method underscores the importance of not relying solely on file extensions to determine the safety of a file. Organizations should implement strict file validation processes and educate users about the risks of opening unexpected files, even if they appear to be from trusted sources. In conclusion, the use of disguised .desktop files by APT36 is a reminder of the evolving nature of cyber threats. It emphasizes the need for continuous vigilance, robust security measures, and ongoing user education to mitigate the risks posed by sophisticated threat actors.
www.cyberhub.blog
August 4, 2025 at 4:40 AM
APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials
APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials
cybersecuritynews.com
August 5, 2025 at 2:03 PM
Oh, also should note that APT36 is sometimes called "Transparent Tribe" though that's because Proofpoint called a campaign "Operation Transparent Tribe" rather than using it as a group name (www.proofpoint.com/sites/defaul...).
www.proofpoint.com
May 16, 2025 at 3:08 PM
ClickFix Malware Campaign Now Hits Linux ClickFix Malware Campaign Now Hits Linux Post Views: 168 Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos. Reading Time: 3 Minutes APT36 Launches Cross-Platform ClickFix Attacks, Now T...

| Details | Interest | Feed |
Origin
www.blackhatethicalhacking.com
May 26, 2025 at 1:30 PM
# APT36 hackers abuse # Linux .desktop files to install # malware in new attacks https://www. bleepingcomputer.com/news/secu rity/apt36-hackers-abuse-linux-desktop-files-to-install-malware/ # Pakistan # cybersecurity # FOSS

Interest | Match | Feed
Origin
mastodon.thenewoil.org
August 23, 2025 at 7:01 AM