HomeSecurityTransparent Tribe: New RAT attacks against the Indian Government

Transparent Tribe: New RAT attacks against the Indian Government

The threat actor known as Transparent Tribe is behind a new set of attacks targeting Indian government, academic, and strategic entities with a remote access Trojan (RAT) that gives them control of compromised systems.

See also: Silver Fox targets Indian users with ValleyRAT malware

Transparent Tribe

“ The campaign uses deceptive delivery techniques, including a forged Windows shortcut (LNK) file that pretends to be a legitimate PDF document and contains full PDF content to avoid user suspicion ,” CYFIRMA said in a technical report.

Transparent Tribe, also known as APT36, is a hacker group known for carrying out cyber espionage campaigns against Indian organizations. It is believed to be of Indian origin, state-backed, and has been active since at least 2013.

The threat actor has an ever-evolving arsenal of RATs to achieve its goals. Some of the Trojans used by Transparent Tribe in recent years include CapraRAT, Crimson RAT, ElizaRAT , and DeskRAT.

The latest set of attacks began with a spear-phishing email containing a ZIP archive with an LNK file disguised as a PDF. Opening the archive triggers the execution of a remote HTML Application (HTA) script using “mshta.exe” that decrypts and loads the final RAT payload directly into memory. At the same time, the HTA downloads and opens a deceptive PDF document to avoid user suspicion.

See also: WebRAT malware distributed via fake PoC exploits on GitHub

Transparent Tribe: New RAT attacks against the Indian Government

A notable feature of the malware is its ability to adapt its persistence method based on the antivirus solutions installed on the infected machine.

If Kaspersky, it creates a working directory under “C:\Users\Public\core,” writes an encrypted HTA payload to disk, and establishes persistence by dropping a LNK file into the Windows Startup folder that launches the HTA script using “mshta.exe.”

If detected Quick Healestablishes persistence by creating a batch file and a malicious LNK file in the Windows Startup folder, writing the HTA payload to disk, and then calling it using the batch script.

If Avast, AVG or Avira, it works by directly copying the payload to the Startup directory and executing it.

If no recognized antivirus solution is detected, it falls back to a combination of batch file execution, registry-based persistence, and payload deployment before launching the batch script.

The second HTA file includes a DLL named “iinneldc.dll” that acts as a full-featured RAT, supporting remote system control, file management, data extraction, screenshot capture, clipboard manipulation, and process control.

See also: Wonderland: Android malware combines dropper, SMS theft and RAT capabilities

Transparent Tribe: New RAT attacks against the Indian Government

In recent weeks, APT36 has also been linked to another campaign that leverages a malicious shortcut file disguised as a government advisory PDF (“NCERT-Whatsapp-Advisory.pdf.lnk”) to deliver a .NET-based loader, which then drops additional executables and malicious DLLs to establish remote command execution, system identity, and long-term access.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS