Pakistani threat actor APT36, also known as Transparent Tribe, has launched a sophisticated cyber espionage campaign against Indian government agencies, using a new Python-based ELF malware.
See also: Python-based WhatsApp worm spreads Eternidade Stealer

This attack marks a significant escalation in the group's capabilities, demonstrating their increasing technical maturity and ability to adapt to Linux operating systems.
The campaign focuses on targeted emails (spear-phishing) containing malicious Linux shortcut files, which are designed to mislead government employees.
When recipients extract and open these files, the malware silently downloads and executes malicious components in the background, while simultaneously displaying harmless-looking content to the user.
See also: New Python library nightMARE for malware analysis

This dual strategy allows attackers to remain invisible while simultaneously establishing permanent access to critical infrastructure. APT36’s shift to targeting Linux represents a strategic evolution in their operational tactics.
The group has traditionally focused on attacks on Windows systems, but this new campaign shows their commitment to targeting the BOSS operating system, which is widely used in Indian government agencies. By adapting their tools to exploit multiple platforms, the attackers are significantly expanding their attack surface and operational effectiveness.
Cyfirma security analysts discovered the malware after discovering weaponized .desktop files being distributed through targeted phishing campaigns. Researchers observed that the infection chain begins with a deceptive compressed archive containing the malicious shortcut and triggers a multi-stage malware delivery process.
See also: Malicious PyPI soopsocks package infected 2,653 systems

When executed, the shortcut downloads a fake PDF file to distract the user, while simultaneously downloading and installing the real ELF malware from servers controlled by the attackers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
