The threat actor known as Transparent Tribe is behind a new set of attacks targeting Indian government, academic, and strategic entities with a remote access Trojan (RAT) that gives them control of compromised systems.
See also: Silver Fox targets Indian users with ValleyRAT malware

“ The campaign uses deceptive delivery techniques, including a forged Windows shortcut (LNK) file that pretends to be a legitimate PDF document and contains full PDF content to avoid user suspicion ,” CYFIRMA said in a technical report.
Transparent Tribe, also known as APT36, is a hacker group known for carrying out cyber espionage campaigns against Indian organizations. It is believed to be of Indian origin, state-backed, and has been active since at least 2013.
The threat actor has an ever-evolving arsenal of RATs to achieve its goals. Some of the Trojans used by Transparent Tribe in recent years include CapraRAT, Crimson RAT, ElizaRAT , and DeskRAT.
The latest set of attacks began with a spear-phishing email containing a ZIP archive with an LNK file disguised as a PDF. Opening the archive triggers the execution of a remote HTML Application (HTA) script using “mshta.exe” that decrypts and loads the final RAT payload directly into memory. At the same time, the HTA downloads and opens a deceptive PDF document to avoid user suspicion.
See also: WebRAT malware distributed via fake PoC exploits on GitHub

A notable feature of the malware is its ability to adapt its persistence method based on the antivirus solutions installed on the infected machine.
If Kaspersky, it creates a working directory under “C:\Users\Public\core,” writes an encrypted HTA payload to disk, and establishes persistence by dropping a LNK file into the Windows Startup folder that launches the HTA script using “mshta.exe.”
If detected Quick Healestablishes persistence by creating a batch file and a malicious LNK file in the Windows Startup folder, writing the HTA payload to disk, and then calling it using the batch script.
If Avast, AVG or Avira, it works by directly copying the payload to the Startup directory and executing it.
If no recognized antivirus solution is detected, it falls back to a combination of batch file execution, registry-based persistence, and payload deployment before launching the batch script.
The second HTA file includes a DLL named “iinneldc.dll” that acts as a full-featured RAT, supporting remote system control, file management, data extraction, screenshot capture, clipboard manipulation, and process control.
See also: Wonderland: Android malware combines dropper, SMS theft and RAT capabilities

In recent weeks, APT36 has also been linked to another campaign that leverages a malicious shortcut file disguised as a government advisory PDF (“NCERT-Whatsapp-Advisory.pdf.lnk”) to deliver a .NET-based loader, which then drops additional executables and malicious DLLs to establish remote command execution, system identity, and long-term access.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
