logo

A look into APT36's (Transparent Tribe) tradecraft

ID: 74f3a8f1-2f77-4a80-afd8-c5681deb23f1

STIX ID: report--74f3a8f1-2f77-4a80-afd8-c5681deb23f1

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2020-11-04

Last Modified Date: 2020-11-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes Transparent Tribe (APT36) tradecraft and the Crimson RAT malware used in espionage campaigns against military and government targets—primarily focused on India—since 2013. It documents a multi-stage infection chain: a macro-enabled lure document (Kashmir_conflict_actions.docx) that queries a remote SQL C2 (Datroapp.mssql.somee.com) to drop a second-stage PE (TrayIcos.exe) which loads an embedded .NET assembly (Random.dll) that ultimately executes Crimson RAT (TrayIcos.exe final). The analysis includes static and dynamic excerpts, persistence via HKCU Run, unencrypted TCP C2 communications, command capabilities (screen capture, process management, file transfer, remote execution), and sample metadata/MD5s for IOC use.