Unveiling Transparent Tribe (APT 36) Report
ID: c76daf53-5163-4eb8-9898-8e9ee403bad5
STIX ID: report--c76daf53-5163-4eb8-9898-8e9ee403bad5
Threat Score
90/100
Uploaded: 2026-08-11
Published Date: 2026-01-16
Last Modified Date: 2026-01-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Aryaka Threat Research Labs report documents active, targeted espionage campaigns by Transparent Tribe (APT36) against Indian government and defense organisations, describing phishing-delivered LNK/HTA and PPAM lures that deploy GETA RAT on Windows, a Go/PyInstaller-based ARES RAT on Linux, and a Go-based Desk RAT using WebSocket C2. The analysis details multi-stage in-memory execution (XAML deserialization, BinaryFormatter), persistence mechanisms (Startup, HKCU Run, systemd user services), encrypted TCP and WebSocket command-and-control with regular beaconing/heartbeat patterns, USB and filesystem collection, screenshot and credential theft, plus IOCs (domains, IPs, SHA256 hashes) and mappings to MITRE ATT&CK techniques for detection and mitigation.
