logo

Operation_C-Major__2020__Operation_Honey_Trap_APT36_Targets_Defense_Organizations_in_India.pdf

ID: 2059209f-1a64-4384-ad21-b6a063402b1f

STIX ID: report--2059209f-1a64-4384-ad21-b6a063402b1f

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2020-07-10

Last Modified Date: 2020-07-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Operation 'Honey Trap' — APT36 spear-phishing campaign:** Seqrite documents an active APT36 (Pakistan-linked) operation using honeytrap social engineering (fake attractive female profiles) to lure Indian defence and government personnel into opening macro-laden documents or ZIP/RAR attachments; these deploy a MSIL Crimson RAT (data-stealing RAT) via two infection chains (macro-based dropper and EXE-in-ZIP dropper), with detailed RAT capabilities and multiple IOCs provided.