# Transparent Tribe

> As of 2026-09-16, Transparent Tribe is a threat actor tracked by Threadlinqs Intelligence across 9 threats spanning apt, malware. ATT&CK coverage spans 116 techniques across 15 tactics in 9 of 9 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel).

- **Tracked threats:** 9
- **Categories:** APT, MALWARE
- **As of:** 2026-09-16

## ATT&CK techniques observed

116 techniques observed across 9 of 9 tracked threats. Tactics: Stealth (formerly Defense Evasion) (21), Command and Control (15), Resource Development (14), Discovery (12), Collection (11), Execution (11).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 6 of 9 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 6 of 9 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 6 of 9 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 6 of 9 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 6 of 9 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 6 of 9 tracked threats
- [T1566.001](https://intel.threadlinqs.com/technique/T1566.001) Phishing: Spearphishing Attachment — Initial Access — observed in 6 of 9 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 5 of 9 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 5 of 9 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 4 of 9 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 4 of 9 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 4 of 9 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 4 of 9 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 4 of 9 tracked threats
- [T1547.001](https://intel.threadlinqs.com/technique/T1547.001) Registry Run Keys / Startup Folder — Persistence — observed in 4 of 9 tracked threats

## Tracked threats

- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and Afghanistan Government/Defense Targets](https://intel.threadlinqs.com/threat/TL-2026-2545) — HIGH
- [PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked)](https://intel.threadlinqs.com/threat/TL-2026-2006) — HIGH
- [Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to Target Indian Government Job Seekers](https://intel.threadlinqs.com/threat/TL-2026-1297) — HIGH
- [SHEETCREEP: C# Windows RAT Abusing the Google Sheets API v4 for Command-and-Control (APT36 / Transparent Tribe)](https://intel.threadlinqs.com/threat/TL-2026-0784) — HIGH
- [AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)](https://intel.threadlinqs.com/threat/TL-2026-0745) — HIGH
- [Operation XENOFISCAL — SideCopy (Transparent Tribe / APT36 umbrella) Deploys Persistent Customized XenoRAT 1.8.7 Against the Afghanistan Ministry of Finance](https://intel.threadlinqs.com/threat/TL-2026-0625) — HIGH
- [Transparent Tribe (APT36) AI-Assisted Vibeware Campaign — 14+ Malware Families Across 6+ C2 Channels](https://intel.threadlinqs.com/threat/TL-2026-0189) — HIGH
- [APT36 "Vibeware" Campaign: AI-Assisted Malware Industrialization Targets Indian and Afghan Government](https://intel.threadlinqs.com/threat/TL-2026-2123) — HIGH
- [APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform Espionage](https://intel.threadlinqs.com/threat/TL-2026-0106) — HIGH

## Related CVEs

5 CVEs referenced by tracked Transparent Tribe activity.

- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Transparent%20Tribe
