The Indian defense sector and government-aligned organizations have been targeted by multiple RAT campaigns designed to compromise Windows and Linux environments with remote access trojans capable of stealing sensitive data and securing continuous access to the infected machines.
See also: New 'ZeroDayRAT' kit allows complete compromise of iOS and Android devices

The campaigns are characterized by the use of malware families such as Geta RAT, Ares RAT , and DeskRAT, often attributed to Pakistan-aligned threat groups tracked as SideCopy and APT36 (also known as Transparent Tribe). Active since at least 2019, SideCopy is believed to operate as a subdivision of Transparent Tribe.
“Overall, these campaigns reinforce a familiar yet evolving narrative,” said Aditya K. Sood, vice president of Security Engineering and AI Strategy at Aryaka. “Transparent Tribe and SideCopy aren’t reinventing espionage — they’re improving it.”
“By expanding system coverage, emphasizing memory-intensive techniques, and experimenting with new delivery methods, this ecosystem continues to operate below the noise floor while maintaining strategic focus.“
Common to all campaigns is the use of phishing emails containing malicious attachments or embedded download links that lead potential targets to infrastructure controlled by the attackers. These initial access mechanisms act as conduits for Windows shortcuts (LNK), ELF binaries, and PowerPoint Add-In files that, when opened, initiate a multi-layered process to install the trojans.
See also: Bloody Wolf targets Uzbekistan and Russia with NetSupport RAT

The malware families are designed to provide persistent remote access, enable system reconnaissance, collect data, execute commands, and facilitate long-term post-breach operations in both Windows and Linux environments.
Geta RAT supports various commands to collect system information, enumerate running processes, terminate a specified process, list installed applications, collect credentials, retrieve and replace clipboard contents with data provided by the attacker, take screenshots, perform file operations, execute arbitrary shell commands, and collect data from connected USB devices.
Alongside this Windows-focused campaign, there is a Linux variant that uses a Go binary as a starting point to install a Python-based Ares RAT via a shell script downloaded from an external server. Like Geta RAT, Ares RAT can also execute a wide range of commands to collect sensitive data and execute Python scripts or commands issued by the attacker.
See also: Compromised dYdX packages on npm and PyPI distribute wallet thieves and RATs

Aryaka also observed another campaign where the Golang malware, DeskRAT, is delivered via a malicious PowerPoint Add-In file that runs an embedded macro to establish outbound communication with a remote server to retrieve the malware. APT36’s use of DeskRAT was documented by Sekoia and QiAnXin XLab in October 2025.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
