HomeSecurityAPT36 attacks BOSS Linux systems via ZIP files

APT36 attacks BOSS Linux systems via ZIP files

The Pakistan-based cyber espionage group APT36 , also known as Transparent Tribe , has significantly upgraded its capabilities, launching a sophisticated campaign specifically targeting Indian defense personnel, leveraging malicious ZIP files to compromise BOSS Linux systems .

See also: Sudo vulnerabilities allow root access on Linux distributions

BOSS Linux ZIP

This development marks a significant change in the group's operational tactics, as it moves from traditional attacks on Windows systems to Linux-oriented infiltration methods, taking advantage of the widespread use of BOSS Linux by Indian government agencies.

According to CYFIRMA, the campaign involves a multi-stage infiltration process, starting with carefully crafted phishing emails that contain attached ZIP files named “Cyber-Security-Advisory.zip”.

After decompression, the file reveals a malicious .desktop named “Cyber-Security-Advisory.desktop” and MD5 hash: 6eb04445cad300c2878e8fbd3cb60b52.

See also: CISA added Linux kernel vulnerability to the KEV List

This Linux shortcut file contains sophisticated command sequences , designed to run silently, without being noticed by the user. The malicious .desktop file exploits key parameters:

  • Type=Application, which ensures execution by the system,
  • Terminal=false, so that no terminal window appears,
  • and Icon=libreoffice-impress, which disguises it as a valid presentation.
APT36 attacks BOSS Linux systems via ZIP files
APT36 attacks BOSS Linux systems via ZIP files

The built-in Bash commands change the working directory to /tmp and run two curl commands .

The first command downloads the file “slide.pptx” from the domain sorlastore.com, which is controlled by the attackers. Although the extension suggests a presentation, the file contains an HTML iframe that displays a deceptive blog page.

At the same time, the second curl downloads the main malicious payload —an executable ELF file named “BOSS.elf” (MD5: 18cf1e3be0e95be666c11d1dbde4588e)—which is stored locally as “client.elf” and executed in the background using the nohup, for continuous and persistent operation.

See also: New Chaos RAT variants attack Windows and Linux systems

Based on the above, what is evident is the increasing shift by threat groups, such as APT36, towards more specialized and less traditional attacks. Targeting BOSS Linux systems via ZIP files, a Debian- based operating system widely used by Indian government agencies , shows that cyberspies are adapting to the technological infrastructure of each target.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS