The Pakistan-based cyber espionage group APT36 , also known as Transparent Tribe , has significantly upgraded its capabilities, launching a sophisticated campaign specifically targeting Indian defense personnel, leveraging malicious ZIP files to compromise BOSS Linux systems .
See also: Sudo vulnerabilities allow root access on Linux distributions

This development marks a significant change in the group's operational tactics, as it moves from traditional attacks on Windows systems to Linux-oriented infiltration methods, taking advantage of the widespread use of BOSS Linux by Indian government agencies.
According to CYFIRMA, the campaign involves a multi-stage infiltration process, starting with carefully crafted phishing emails that contain attached ZIP files named “Cyber-Security-Advisory.zip”.
After decompression, the file reveals a malicious .desktop named “Cyber-Security-Advisory.desktop” and MD5 hash: 6eb04445cad300c2878e8fbd3cb60b52.
See also: CISA added Linux kernel vulnerability to the KEV List
This Linux shortcut file contains sophisticated command sequences , designed to run silently, without being noticed by the user. The malicious .desktop file exploits key parameters:
Type=Application, which ensures execution by the system,Terminal=false, so that no terminal window appears,- and
Icon=libreoffice-impress, which disguises it as a valid presentation.

The built-in Bash commands change the working directory to /tmp and run two curl commands .
The first command downloads the file “slide.pptx” from the domain sorlastore.com, which is controlled by the attackers. Although the extension suggests a presentation, the file contains an HTML iframe that displays a deceptive blog page.
At the same time, the second curl downloads the main malicious payload —an executable ELF file named “BOSS.elf” (MD5: 18cf1e3be0e95be666c11d1dbde4588e)—which is stored locally as “client.elf” and executed in the background using the nohup, for continuous and persistent operation.
See also: New Chaos RAT variants attack Windows and Linux systems
Based on the above, what is evident is the increasing shift by threat groups, such as APT36, towards more specialized and less traditional attacks. Targeting BOSS Linux systems via ZIP files, a Debian- based operating system widely used by Indian government agencies , shows that cyberspies are adapting to the technological infrastructure of each target.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
