A look into APT36's (Transparent Tribe) tradecraft
ID: 74f3a8f1-2f77-4a80-afd8-c5681deb23f1
STIX ID: report--74f3a8f1-2f77-4a80-afd8-c5681deb23f1
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2020-11-04
Last Modified Date: 2020-11-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes Transparent Tribe (APT36) tradecraft and the Crimson RAT malware used in espionage campaigns against military and government targets—primarily focused on India—since 2013. It documents a multi-stage infection chain: a macro-enabled lure document (Kashmir_conflict_actions.docx) that queries a remote SQL C2 (Datroapp.mssql.somee.com) to drop a second-stage PE (TrayIcos.exe) which loads an embedded .NET assembly (Random.dll) that ultimately executes Crimson RAT (TrayIcos.exe final). The analysis includes static and dynamic excerpts, persistence via HKCU Run, unencrypted TCP C2 communications, command capabilities (screen capture, process management, file transfer, remote execution), and sample metadata/MD5s for IOC use.
