Threat reportAPTTL-2026-0106
APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform Espionage
APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for (TL-2026-0106) is a high-severity advanced persistent threat campaign, first published 2026-02-16. It is attributed to APT36 (Pakistan) with high confidence, maps to 29 MITRE ATT&CK techniques (T1005, T1025, T1027.003), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 1APT36
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-0106
- Threat ID
- TL-2026-0106
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- APT36
- Attribution confidence
- HIGH
- Nation-state nexus
- Pakistan
- Motivation
- ESPIONAGE
- Target sectors
- Military, Government, Defense, Diplomatic, Education
- Target regions
- India, South Asia
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for
Malware and tooling: CapraRAT, CrimsonRAT, ObliqueRAT - S0644
How APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for works
APT36/Transparent Tribe (Pakistan-nexus, ISI-linked) deploys Crimson RAT (.NET) and CapraRAT (Android) for persistent espionage against Indian military, government, defense, diplomatic, and education sectors since 2013. Multi-platform arsenal spanning Windows (CrimsonRAT, ObliqueRAT), Android (CapraRAT, modified AhMyth), and USB worms.
APT36, also known as Transparent Tribe, Earth Karkaddan, Operation C-Major, PROJECTM, and Mythic Leopard, is a Pakistan-nexus advanced persistent threat group active since at least 2013. The group is assessed with high confidence to be linked to Pakistan's Inter-Services Intelligence (ISI) directorate, conducting persistent cyber-espionage operations primarily against Indian military and government targets within the India-Pakistan geopolitical context.
**V1 CORRECTION: The v1 seed data claimed 'Indian startup ecosystem' targeting. This is FABRICATED. All verified primary sources (Cisco Talos, Trend Micro, Kaspersky, SentinelOne, Proofpoint) consistently document targeting of Indian military, government, defense, diplomatic, and education sectors. The group expanded to education (universities/colleges) in late 2021 (Cisco Talos), NOT startups. No evidence of specific startup ecosystem targeting exists in any primary source.**
**WINDOWS ARSENAL:**
1. **Crimson RAT** — The group's primary implant since at least 2016. Written in .NET with minimal obfuscation (Trend Micro notes this may indicate limited funding). Capabilities: file enumeration, process listing, screenshot capture, keylogging module, USB worm module, browser credential theft, arbitrary command execution, file exfiltration/deletion, drive listing, system info collection. Communicates over TCP to C2 servers. Continuously updated with new capabilities and obfuscation. Delivered primarily via malicious Office documents (XLS/DOC) with VBA macros that decrypt embedded PE payloads hidden in text boxes.
2. **ObliqueRAT** — C/C++-based implant discovered by Cisco Talos (Feb 2020). Reserved for hyper-targeted operations where stealth is critical. Capabilities: system info, drive enumeration, file search/exfiltration (ZIP compressed), command execution, file download/deletion, process listing/killing, reverse shell. Evolved delivery: initially embedded in maldocs, later hosted on compromised legitimate websites (e.g., iiaonline.in — Indian Industries Association). Hidden inside BMP image files using steganography.
3. **Custom downloaders/droppers** — Lightweight tools for quick deployment, containing limited capabilities compared to CrimsonRAT/ObliqueRAT.
**ANDROID ARSENAL:**
4. **CapraRAT** — Custom Android RAT with design similarities to CrimsonRAT (shared function names, commands, capabilities — documented by Trend Micro Jan 2022). Observed since 2017. Capabilities: GPS location, SMS read/send, contacts, call history, audio recording, camera, screen recording, file browsing/upload/deletion, process management. Delivered as trojanized apps: YouTube mimics, TikTok, gaming apps, weapons enthusiast apps, romance/honeytrap apps. SentinelOne documented 'CapraTube Remix' campaign (2024) targeting gamers and weapons enthusiasts with WebView-wrapped YouTube/CrazyGames apps.
5. **Modified AhMyth RAT** — Open-source Android RAT customized by Transparent Tribe. Distributed as fake Aarogya Setu COVID-19 tracking app and porn-themed apps. Enhanced with audio surveillance, SMS deletion, auto-download of contacts/messages/WhatsApp media. C2 configuration fetched from external URL (not hardcoded).
6. **StealthAgent** — Earlier Android spyware (2018) intercepting calls/messages, tracking location, stealing photos.
**DELIVERY METHODS:** - Spearphishing emails with malicious Office documents (VBA macros) — primary vector - Honeytrap social engineering (fake profiles of women, romance-themed lures) - Fake government documents (military notices, pay commission updates, COVID-19 tracking) - Fake conference materials (agenda documents for defense conferences) - Fake domains: studentsportal[.]live, 7thcpcupdates[.]info, clawsindia[.]com, sharingmymedia[.]com - USB worm propagation module built into CrimsonRAT - Malicious Android APKs distributed via WhatsApp groups and phishing links - Trojanized apps mimicking legitimate services (YouTube, TikTok, COVID tracking)
**INFRASTRUCTURE:** Cisco Talos identified ZainHosting (Lahore, Pakistan) as infrastructure provider — registered ~2,000 domains including malicious ones. Email address rupees001@gmail.com linked to both legitimate hosting business and Transparent Tribe infrastructure. Uses typo-squatted domains (geo-news[.]tv mimicking geo[.]tv) with shared SSL certificates across malicious infrastructure.
MITRE ATT&CK techniques used in TL-2026-0106
collection
T1005 Data from Local System; T1025 Data from Removable Media; T1056.001 Keylogging; T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture; T1125 Video Capture
defense-evasion
T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1053.005 Scheduled Task; T1059.005 Visual Basic; T1204.002 Malicious File
discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery
command-and-control
T1071.001 Web Protocols; T1102 Web Service; T1571 Non-Standard Port
lateral-movement
T1091 Replication Through Removable Media
persistence
T1547.001 Registry Run Keys / Startup Folder
credential-access
T1555.003 Credentials from Web Browsers
initial-access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service
resource-development
Remediation for APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for
Patches
- N/A — social engineering delivery, no specific CVEs
Immediate actions
- Block known Transparent Tribe C2 domains: shareboxs.net, sharingmymedia.com, tryanotherhorse.com, viral91.xyz, geo-news.tv
- Block known C2 IPs: 173.249.50.243, 173.212.206.227, 89.45.67.160, 212.8.240.221
- Disable Office VBA macros via GPO for non-essential users
- Block sideloaded Android APKs — enforce Google Play-only installation policy for military/government devices
- Monitor for .NET processes with CrimsonRAT behavioral patterns (TCP C2 communication, keylogger module deployment)
Workarounds
- Disable macro execution in Office documents from external sources
- Block execution of .NET binaries from %TEMP% and %APPDATA% directories
- Android: do not install APKs from untrusted sources, especially via WhatsApp links
Longer-term hardening
- Implement email gateway sandboxing for Office document attachments
- Deploy EDR with .NET assembly analysis for CrimsonRAT detection
- Mobile Device Management (MDM) for government/military personnel — restrict app installation sources
- User awareness training: honeytrap social engineering, fake government document lures
- Network monitoring for TCP connections to known Transparent Tribe infrastructure patterns
- Monitor USB device connections — CrimsonRAT includes USB worm module
Timeline of APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for
- Transparent Tribe first observed by security researchers. Kaspersky traces activity back to 2013, initially targeting Indian military and government personnel with early variants of espionage tools. Source: https://securelist.com/transparent-tribe-part-2/98233/
- Palo Alto Unit42 publishes link between 'ProjectM' (Pakistan-based actor) and Operation Transparent Tribe, establishing the Pakistan-nexus attribution. Source: https://unit42.paloaltonetworks.com/unit42-projectm-link-found-between-pakistani-actor-and-operation-transparent-tribe/
- Earliest observed CapraRAT Android samples. Trend Micro identifies com.example.appcode.appcode package with public test certificate, suggesting early development phase. C2 hosted on android.viral91.xyz subdomain. Source: https://www.trendmicro.com/en_us/research/22/a/investigating-apt36-or-earth-karkaddans-attack-chain-and-malware.html
- Amnesty International publishes report on Pakistani agencies using Transparent Tribe's CrimsonRAT against human rights activists in Pakistan, expanding known targeting beyond Indian government/military. Source: https://www.amnesty.org/en/documents/asa33/8366/2018/en/
- Cisco Talos discovers ObliqueRAT, a C/C++-based implant attributed to Transparent Tribe. Reserved for hyper-targeted operations with stealth priority. Distributed via malicious documents. Source: https://blog.talosintelligence.com/obliquerat-hits-victims-via-maldocs/
- Transparent Tribe distributes fake Aarogya Setu COVID-19 tracking app (modified AhMyth RAT) targeting Indian military via WhatsApp groups. Indian Army issues warning about Pakistani intelligence operatives distributing the fake app. Source: https://securelist.com/transparent-tribe-part-2/98233/
- Team Cymru publishes comprehensive Transparent Tribe infrastructure mapping, documenting RDP certificate pattern 'WIN-P9NRMH5G6M8' across C2 servers. Source: https://team-cymru.com/blog/2021/07/02/transparent-tribe-apt-infrastructure-mapping-2/
- Transparent Tribe begins targeting Indian educational institutions (universities, colleges) — first documented expansion beyond military/government. Cisco Talos identifies studentsportal[.]live, studentsportal[.]website domains and ZainHosting (Lahore) infrastructure. Source: https://blog.talosintelligence.com/transparent-tribe-targets-education/
- Trend Micro publishes comprehensive Earth Karkaddan (APT36) analysis documenting full attack chain: spearphishing → macro → Crimson RAT, plus CapraRAT Android component with CrimsonRAT code similarities. Source: https://www.trendmicro.com/en_us/research/22/a/investigating-apt36-or-earth-karkaddans-attack-chain-and-malware.html
- SentinelOne documents CapraTube Remix: updated CapraRAT APKs targeting gamers (CrazyGames), weapons enthusiasts (Forgotten Weapons YouTube), and TikTok users. Updated for Android 8.0+ compatibility. C2: shareboxs.net / 173.249.50.243:18582. Source: https://www.sentinelone.com/labs/capratube-remix-transparent-tribes-android-spyware-targeting-gamers-weapons-enthusiasts/
- As of 2026-05-29, APT36/Transparent Tribe remains highly active and undisrupted, with CYFIRMA (Dec 2025) and The Hacker News (Jan 2026) documenting new weaponized-LNK/HTA campaigns deploying Crimson RAT, CapraRAT, ElizaRAT and DeskRAT against Indian government and academia. Bitdefender (Mar 2026) reports the group escalating to AI-generated "vibeware" implants in Nim/Zig/Crystal, plus CERT-In 2025 advisories, confirming ACTIVE status with no takedown.
Sources cited for APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for
- Cisco Talos — Transparent Tribe Targets Education Sector
- Cisco Talos — Transparent Tribe APT Expands Windows Malware Arsenal
- Trend Micro — Earth Karkaddan (APT36) Attack Chain and Malware Arsenal
- Kaspersky — Transparent Tribe Evolution Part 2 (Android RAT + ObliqueRAT)
- SentinelOne — CapraTube Remix (CapraRAT Gamers/Weapons Targeting)
- Amnesty International — Pakistan Digital Surveillance (CrimsonRAT vs Human Rights)
- Team Cymru — Transparent Tribe Infrastructure Mapping
- Palo Alto Unit42 — ProjectM Link to Transparent Tribe
- Cisco Talos — ObliqueRAT Hits Victims via Maldocs
- K7 Computing — Transparent Tribe Targets Educational Institution
Detection coverage for TL-2026-0106
As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0106 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.