HomeSecurityMythic Leopard hacking group attacks Indian government

Mythic Leopard hacking group attacks Indian government

A new campaign by the hacking group monitored as APT36, also known as “Transparent Tribe” or “Mythic Leopard,” has been discovered. The group is using a new custom malware and is carrying out attacks against the Indian government.

See also: Microsoft will block vulnerable drivers in Windows 10, Windows 11

Mythic Leopard hacking group attacks Indian government

This Pakistan-based threat actor has been active since at least 2016 and its targets are almost exclusively Indian defense and government entities.

The group's goal is to collect information through cyberespionage, so the APT36 group is considered to be a state-sponsored threat actor from Pakistan.

Cisco Talos researchers today published a report detailing their recent findings on the activity of the APT36 group and highlighting some interesting new changes in the threat actor's tactics.

New vector of infection

The most interesting aspect of the new campaign is the use of Kavach authentication apps targeting Indian government employees.

Kavach Authentication is an OTP application written by the National Informatics Centre of India for secure multi-factor authentication in critical IT systems.

Mythic Leopard

The application is used extensively by military personnel or Indian government employees who need to access IT resources such as email services or databases.

See also: Europol dismantles massive investment fraud operation

The distribution of fake Kavach installers is done through fake websites that are clones of legitimate Indian government sites, such as that of the Defence Services Officers Institute.

Mythic Leopard

Victims receive a copy of a legitimate Kavach installer and a malicious payload that automatically starts the infection process with the malware of the threat actor's choice.

Both cloned websites and the use of malware masquerading as legitimate and well-known applications are common and previously observed tactics of the APT36 group.

New custom malware

The threat actor still uses CrimsonRAT, which was first detected in 2020 campaigns, but the malware has evolved to offer more capabilities to its operators.

CrimsonRAT is APT36's main tool, which can steal browser credentials, list running processes, retrieve additional payloads from the C2, and take screenshots.

See also: Mars Stealer malware distributed via OpenOffice ads on Google

In its 2022 version, CrimsonRAT also uses a keylogger, supports the execution of arbitrary commands on the compromised system, can read file contents, delete files, and much more.

Mythical Leopard

Another tool used in recent campaigns is a lightweight .NET remote access trojan that is more basic compared to CrimsonRAT but still offers powerful functionality.

The APT36 group is likely using this second implant for redundancy, while it may simply be an early development version of a new custom RAT that will be enhanced with more features in the future.

In 2021, the APT36 group also used ObliqueRAT in very limited targeted attacks against government personnel.

The "Mythic Leopard" team continues to evolve and remains highly active, improving its implants and regularly renewing infection vectors to remain undetectable.

Summary of conclusions

Mythic Leopard is a very active APT group in the Indian subcontinent. Their primary targets have been government and military personnel in Afghanistan and India. This campaign furthers this targeting and their central goal of establishing long-term access for espionage. The use of multiple types of delivery vehicles and file formats indicates that the group is aggressively attempting to infect their targets with their implants, such as CrimsonRAT. They have continued to use fake domains masquerading as government and quasi-government entities, as well as using content-hosting domains to host malware. While not very sophisticated, this is a highly motivated and persistent adversary that is constantly evolving tactics to infect its targets.

Organizations should remain vigilant against such threats, as they are likely to proliferate in the future. Defense-in-depth strategies based on a risk analysis approach can offer better results in prevention. However, this should always be complemented by a good incident response plan, which will be reviewed and improved each time it is tested in real-world engagements.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS