logo

Operation_C-Major__2022__CiscoTalos_TransparentTribe-bespoke-malware-target-Indian-gov-officials_03-29-2022.pdf

ID: 108819a3-1347-4ab5-8cd3-e381ab8730e1

STIX ID: report--108819a3-1347-4ab5-8cd3-e381ab8730e1

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2022-04-01

Last Modified Date: 2022-04-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Cisco Talos observed an ongoing Transparent Tribe (APT36 / Mythic Leopard) campaign targeting Indian government and military personnel that uses CrimsonRAT plus new lightweight .NET implants and Python-based stagers; attackers employ diverse delivery vectors (maldocs, IMG, VHDX, RAR, fake Kavach installers), cloned/typo-squatted government domains, and multiple C2 URLs — the report includes technical analysis, code snippets, IOCs (hashes, domains, URLs, file types) and detection/mitigation guidance.