A new report from Check Point says that Pakistani hackers APT36 have targeted high-profile entities in India with ElizaRATin cyber espionage attacks.

Check Point researchers monitoring the use of ElizaRAT, created by the Pakistani state-sponsored hacking group APT36 (or Transparent Tribe). During 2024, several campaigns using the trojan were detected.
ElizaRAT malware
ElizaRAT has been in use since at least September 2023. Infections are often caused by Windows Control Panel (CPL) files distributed via Google Storage links, which in turn are likely distributed via phishing emails. ElizaRAT uses cloud services such as Google, Telegram, and Slack for distribution and command and control (C2) communication.
See also: RomCom hackers target Ukrainian services with SingleCamper RAT
ElizaRAT is written in .NET and uses Costura to embed . NET and assembly modules. It tries to trick victims with various baits (documents or videos).
In most samples, it uses IWSHshell to create Windows shortcuts to the malware. It also uses SQLite as a resource to store files from the victim's machine to a local database ( before theft). ElizaRAT also creates and stores a unique victim identifier in a separate file on the machine.
Pakistani hackers APT36 have improved ElizaRAT
Since late 2023, ElizaRAT's execution methods, evasion capabilities, and C2 communication have evolved.
Check Point Research observed that in three campaigns, from late 2023 to early 2024, the attacker used a different variant of ElizaRAT to download specific second-stage payloads, which automatically collect information.
See also: ScarCruft spreads RokRAT malware via Windows Zero-Day
The researchers shared a technical analysis of each of these campaigns. Their analysis revealed continued improvements in ElizaRAT evasion techniques, leading to a new version called Circle ElizaRAT . A new stealer payload, ApoloStealer , was also introduced .
“The evolution of ElizaRAT reflects APT36’s deliberate efforts to improve its malware to better evade detection and effectively target Indian entities,” Check Point researchers concluded. “The introduction of new payloads, such as ApoloStealer, marks a significant expansion of APT36’s arsenal and suggests that the group is adopting a more flexible, modular approach to payload development. These methods focus primarily on data collection and infiltration, underscoring their continued emphasis on intelligence gathering and espionage.”

What are the best methods for protecting against RAT malware?
The first and most important method of protection is awareness and education. Users need to be aware of the techniques attackers use to spread malware so they can identify and avoid them.
See also: PondRAT malware targets developers with Python packages
Installing reliable security is another essential method of malware protection. This software should include antivirus, anti-spyware, and anti-malware features, as well as phishing protection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
It's also important to keep your operating system and all applications up to date. Updates include security that can protect your computer from the latest threats.
Finally, careful interaction with emails and file attachments is crucial. Never open attachments or click on links from unknown sources as they may contain malware.
Source: www.infosecurity-magazine.com
