Activity timeline
Transparent Tribe appears in 9 tracked threats between and ; the busiest month was 2026-03 with 2 reports.
ATT&CK techniques observed
- T1005 Data from Local System — Collectionobserved in 6 of 9 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 6 of 9 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 6 of 9 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 6 of 9 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 6 of 9 tracked threats
- T1204.002 User Execution: Malicious File — Executionobserved in 6 of 9 tracked threats
- T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 6 of 9 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 5 of 9 tracked threats
- T1113 Screen Capture — Collectionobserved in 5 of 9 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 9 tracked threats
- T1053.005 Scheduled Task — Persistenceobserved in 4 of 9 tracked threats
- T1057 Process Discovery — Discoveryobserved in 4 of 9 tracked threats
- T1102 Web Service — Command and Controlobserved in 4 of 9 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 4 of 9 tracked threats
- T1547.001 Registry Run Keys / Startup Folder — Persistenceobserved in 4 of 9 tracked threats
Tracked threats
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and Afghanistan Government/Defense TargetsHIGH
- PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked)HIGH
- Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to Target Indian Government Job SeekersHIGH
- SHEETCREEP: C# Windows RAT Abusing the Google Sheets API v4 for Command-and-Control (APT36 / Transparent Tribe)HIGH
- AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)HIGH
- Operation XENOFISCAL — SideCopy (Transparent Tribe / APT36 umbrella) Deploys Persistent Customized XenoRAT 1.8.7 Against the Afghanistan Ministry of FinanceHIGH
- Transparent Tribe (APT36) AI-Assisted Vibeware Campaign — 14+ Malware Families Across 6+ C2 ChannelsHIGH
- APT36 "Vibeware" Campaign: AI-Assisted Malware Industrialization Targets Indian and Afghan GovernmentHIGH
- APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform EspionageHIGH