The Transparent Tribe group is involved in campaigns against government and military personnel, revealing a new tool designed to infect USB devices and spread to other systems.
The advanced APT group, previously researched by Proofpoint (.PDF), has been operating since at least 2013 and has previously been linked to attacks against the Indian government and military.

Recently, APT has focused on Afghanistan, however, researchers have documented its presence in approximately 30 countries.
Also known as PROJECTM and MYTHIC LEOPARD, the Transparent Tribe group is described as a "productive" group that engages in "mass espionage campaigns.".
Transparent Tribe focuses on surveillance and espionage, and to achieve these ends, the group is constantly evolving toolkit depending on the intended goal, Kaspersky said in a blog post on Thursday.
The attack chain begins in a classic way, via phishing emails . The bogus emails are sent along with malicious Microsoft Office documents that contain an embedded macro that deploys the group's main payload, the Crimson Remote Access Trojan (RAT).
If a victim activates the macros, the custom .NET Trojan launches and performs a variety of functions, including connecting to a command-and-control (C2) server for data and remote malware updates, stealing files, taking screenshots , and hacking microphones and webcams for audio and video monitoring.
Kaspersky says the Trojan is also capable of stealing files from removable media, recording keys, and stealing credentials stored in browsers.
The Trojan comes in two versions that have been released in 2017, 2018, and at the end of 2019, suggesting that the malware is still in development.
The Transparent Tribe group also uses another .NET malware and a Trojan called Peppy, but a new USB attack tool is of particular interest.
USBWorm consists of two main components, a file stealer for removable drives and a worm capability to migrate to new, vulnerable machines.
If a USB drive is plugged into an infected computer, a copy of the Trojan is silently installed on the removable drive. The malware will list all directories on a drive and then a copy of the Trojan will be stored in the root drive directory. The directory attribute is then changed to “hidden” and a fake Windows icon is used to trick victims into clicking and executing the payload when they try to access the directories.
"This results in hiding and replacing all real directories with a copy of the malware using the same directory name," the researchers note.
Over 200 samples of Transparent Tribe Crimson components were identified between June 2019 and June 2020.
“Over the past 12 months, we have observed a broad campaign against military and diplomatic targets,” Kaspersky researcher Giampaolo Dedola commented. “We do not expect a slowdown in activity from this group in the near future.”
