logo

Operation_C-Major__2021__blog.talosintelligence.com-Transparent_Tribe_APT_expands_its_Windows_malware_arsenal.pdf

ID: c32dfc5d-7c5f-462b-a219-da993599ffbc

STIX ID: report--c32dfc5d-7c5f-462b-a219-da993599ffbc

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2021-05-14

Last Modified Date: 2021-05-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Transparent Tribe (APT36) expanded its Windows malware toolkit by using maldocs and cloned or malicious domains to distribute CrimsonRAT and ObliqueRAT; the group targets Indian military and defense personnel as well as diplomatic, research and conference attendees across South Asia. The report documents social‑engineering lures (military-themed, honeytraps, conference agendas), hosting infrastructure (fake sites, compromised legitimate sites, file-sharing domains), and provides extensive IOCs (domains, URLs, IPs) to support detection and mitigation.