A sophisticated Windows Remote Access Trojan (RAT) called ElizaRAT, developed by APT36 (also known as Transparent Tribe), is abusing the services of major technology companies.
See also: LodaRAT malware: Targets Windows users and steals credentials

This Pakistani threat group is known for targeting Indian government agencies, diplomatic personnel, and military installations. However, it has now expanded its attack surface to include major platforms such as Windows , Linux , and Android .
In addition to this, security analysts at Reco discovered that ElizaRAT exhibits several advanced capabilities:
- Written in .NET with built-in .NET and assembly modules
- Execution via .CPL for evasion
- Utilization of cloud services (Google, Telegram, Slack) for C2 distribution and communication
- Development of decoy documents or videos
- Using IWSHshell for persistence
- SQLite for temporary file storage
- Create and store a unique victim ID
See also: Russian hackers exploit NTLM vulnerability to spread RAT Malware via Phishing emails
ElizaRAT represents a significant advancement in APT36's cyber espionage capabilities.

By leveraging popular cloud and employing sophisticated evasion techniques, the malware poses a serious threat to its targets.
The modular approach and the introduction of new payloads such as ApolloStealer demonstrate APT36's commitment to refining its tools for maximum effectiveness in data theft and espionage operations.
A Remote Access Trojan (RAT), such as ElizaRAT, is a malicious software that invades your computer and allows malicious users to gain remote access and control over your system. This can include monitoring your activities, stealing sensitive information and files, and performing unwanted actions on your computer.
See also: New phishing campaign distributes fileless variant of Remcos RAT
RATs are often used by cybercriminals for malicious purposes, such as stealing personal information, financial data, and committing other fraudulent acts. To protect yourself from RATs, it is important to keep your security software up to date, avoid opening files from unknown sources, and be aware of phishing.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
