HomeSecurityTransparent Tribe: Mass production of malicious applications with AI

Transparent Tribe: Mass production of malicious applications with AI

The Pakistan-linked threat group, known as Transparent Tribe, is the latest hacker group to adopt artificial intelligence (AI) coding tools to attack targets with various malicious applications.

See also: Dust Specter targets Iraqi officials with SPLITDROP and GHOSTFORM

Transparent Tribe
Transparent Tribe: Mass production of malicious applications with AI

This activity is designed to produce a “high volume, moderate quality mass applications” developed using lesser-known programming languages ​​like Nim, Zig, and Crystal and rely on trusted services like Slack, Discord, Supabase, and Google Sheets to go unnoticed, according to new findings from Bitdefender.

The move towards vibe-encoded malware, also known as vibeware, as a means of complicating detection has been characterized by the Romanian cybersecurity vendor as Distributed Denial of Detection (DDoD). In this approach, the idea is not to bypass detection efforts through technical innovation, but rather to flood target environments with exploitable binaries, each using a different language and communication protocol.

At this point, the threat actors are aided by large language models (LLMs), which lower the barrier to cybercrime and bridge the expertise gap by allowing them to generate functional code in unknown languages, either from scratch or by transferring core business logic from more common ones.

See also: Ukraine: APT28 installs BadPaw Loader and MeowMeow Backdoor

Transparent Tribe: Mass production of malicious applications with AI
Transparent Tribe: Mass production of malicious applications with AI

The latest set of attacks has been found to target the Indian government and its embassies in many foreign countries, with APT36 using LinkedIn to identify high-value targets. The attacks have also targeted the Afghan government and several private enterprises, albeit to a lesser extent.

Infection chains likely start with phishing emails containing Windows shortcuts (LNKs) embedded in ZIP files or ISO images. Alternatively, PDF decoys with a prominent “Download Document” button are used to redirect users to a website controlled by the attacker and trigger the download of the same ZIP files.

Regardless of the method used, the LNK file is used to execute PowerShell scripts in memory, which then download and execute the main backdoor and facilitate post‑compromise actions. These include the deployment of known adversary‑simulation tools such as Cobalt Strike and Havoc, indicating a hybrid approach to ensure resilience.

See also: LexisNexis: Hackers leaked stolen data

Transparent Tribe: Mass production of malicious applications with AI
Transparent Tribe: Mass production of malicious applications with AI

Some of the other tools observed as part of the attacks are as follows:

  • Warcode, a custom shellcode loader written in Crystal that is used to reflexively load a Havoc agent directly into memory. NimShellcodeLoader, an experimental counterpart of Warcode that is used for deploying a Cobalt Strike beacon embedded in it.
  • CreepDropper, a malicious .NET software used for delivering and installing additional payloads, including SHEETCREEP, a Go-based infostealer that uses the Microsoft Graph API for C2, and MAILCREEP, a C#-based backdoor that uses Google Sheets for C2.
  • SupaServ, a Rust-based backdoor that creates a primary communication channel via the Supabase platform, with Firebase serving as a fallback. It contains Unicode emojis, indicating that it was likely developed using AI.
  • LuminousStealer, a possible vibe-coded infostealer based on Rust that uses Firebase and Google Drive to extract files that match certain extensions (.txt, .docx, .pdf, .png, .jpg, .xlsx, .pptx, .zip, .rar, .doc, and .xls).
  • CrystalShell, a backdoor written in Crystal that is capable of targeting Windows, Linux, and macOS systems, and uses programmed Discord channel IDs for C2. It supports command execution and host information collection. A variant of the malware has been found to use Slack for C2.
Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS