Operation_C-Major__2020__Operation_Honey_Trap_APT36_Targets_Defense_Organizations_in_India.pdf
ID: 2059209f-1a64-4384-ad21-b6a063402b1f
STIX ID: report--2059209f-1a64-4384-ad21-b6a063402b1f
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2020-07-10
Last Modified Date: 2020-07-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Operation 'Honey Trap' — APT36 spear-phishing campaign:** Seqrite documents an active APT36 (Pakistan-linked) operation using honeytrap social engineering (fake attractive female profiles) to lure Indian defence and government personnel into opening macro-laden documents or ZIP/RAR attachments; these deploy a MSIL Crimson RAT (data-stealing RAT) via two infection chains (macro-based dropper and EXE-in-ZIP dropper), with detailed RAT capabilities and multiple IOCs provided.
