Threadlinqs IntelligenceStart free

Threat actorPakistanTracked since 2026-02

APT36

Also known as:Operation C-MajorCOPPER FIELDSTONEMythic LeopardProjectMTransparent TribeEarth KarkaddanNightmare

As of 2026-09-16, APT36 is a Pakistan-nexus threat actor tracked by Threadlinqs Intelligence across 9 threats spanning apt, malware. Also known as Operation C-Major, COPPER FIELDSTONE, Mythic Leopard, ProjectM. ATT&CK coverage spans 116 techniques across 15 tactics in 9 of 9 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel).

Tracked threats
99 high
First seen
2026-02-16
Last seen
2026-09-16
ATT&CK techniques
116across 9 of 9 threats
Related CVEs
5Referenced by its activity
Attribution
PakistanNation or origin
Nation: Pakistan · 9 tracked threat(s) · Categories: APT, MALWARE

Activity timeline

APT36 appears in 9 tracked threats between and ; the busiest month was 2026-03 with 2 reports.

ATT&CK techniques observed

116 techniques observed across 9 of 9 tracked threats · Stealth (formerly Defense Evasion) (21), Command and Control (15), Resource Development (14), Discovery (12), Collection (11), Execution (11)
  • T1005 Data from Local System — Collectionobserved in 6 of 9 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 6 of 9 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 6 of 9 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 6 of 9 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 6 of 9 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 6 of 9 tracked threats
  • T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 6 of 9 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 5 of 9 tracked threats
  • T1113 Screen Capture — Collectionobserved in 5 of 9 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 9 tracked threats
  • T1053.005 Scheduled Task — Persistenceobserved in 4 of 9 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 4 of 9 tracked threats
  • T1102 Web Service — Command and Controlobserved in 4 of 9 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 4 of 9 tracked threats
  • T1547.001 Registry Run Keys / Startup Folder — Persistenceobserved in 4 of 9 tracked threats

Tracked threats

Related CVEs

5 CVEs referenced by tracked APT36 activity