Operation_C-Major__2022__CiscoTalos_TransparentTribe-bespoke-malware-target-Indian-gov-officials_03-29-2022.pdf
ID: 108819a3-1347-4ab5-8cd3-e381ab8730e1
STIX ID: report--108819a3-1347-4ab5-8cd3-e381ab8730e1
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2022-04-01
Last Modified Date: 2022-04-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Cisco Talos observed an ongoing Transparent Tribe (APT36 / Mythic Leopard) campaign targeting Indian government and military personnel that uses CrimsonRAT plus new lightweight .NET implants and Python-based stagers; attackers employ diverse delivery vectors (maldocs, IMG, VHDX, RAR, fake Kavach installers), cloned/typo-squatted government domains, and multiple C2 URLs — the report includes technical analysis, code snippets, IOCs (hashes, domains, URLs, file types) and detection/mitigation guidance.
