Threat reportAPTTL-2026-0106

APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform Espionage

highACTIVE

APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for (TL-2026-0106) is a high-severity advanced persistent threat campaign, first published 2026-02-16. It is attributed to APT36 (Pakistan) with high confidence, maps to 29 MITRE ATT&CK techniques (T1005, T1025, T1027.003), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
1APT36
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-0106

Threat ID
TL-2026-0106
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
APT36
Attribution confidence
HIGH
Nation-state nexus
Pakistan
Motivation
ESPIONAGE
Target sectors
Military, Government, Defense, Diplomatic, Education
Target regions
India, South Asia
Detection rules
9
Indicators of compromise
32

Malware and tooling in APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for

Malware and tooling: CapraRAT, CrimsonRAT, ObliqueRAT - S0644

How APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for works

APT36/Transparent Tribe (Pakistan-nexus, ISI-linked) deploys Crimson RAT (.NET) and CapraRAT (Android) for persistent espionage against Indian military, government, defense, diplomatic, and education sectors since 2013. Multi-platform arsenal spanning Windows (CrimsonRAT, ObliqueRAT), Android (CapraRAT, modified AhMyth), and USB worms.

APT36, also known as Transparent Tribe, Earth Karkaddan, Operation C-Major, PROJECTM, and Mythic Leopard, is a Pakistan-nexus advanced persistent threat group active since at least 2013. The group is assessed with high confidence to be linked to Pakistan's Inter-Services Intelligence (ISI) directorate, conducting persistent cyber-espionage operations primarily against Indian military and government targets within the India-Pakistan geopolitical context.

**V1 CORRECTION: The v1 seed data claimed 'Indian startup ecosystem' targeting. This is FABRICATED. All verified primary sources (Cisco Talos, Trend Micro, Kaspersky, SentinelOne, Proofpoint) consistently document targeting of Indian military, government, defense, diplomatic, and education sectors. The group expanded to education (universities/colleges) in late 2021 (Cisco Talos), NOT startups. No evidence of specific startup ecosystem targeting exists in any primary source.**

**WINDOWS ARSENAL:**

1. **Crimson RAT** — The group's primary implant since at least 2016. Written in .NET with minimal obfuscation (Trend Micro notes this may indicate limited funding). Capabilities: file enumeration, process listing, screenshot capture, keylogging module, USB worm module, browser credential theft, arbitrary command execution, file exfiltration/deletion, drive listing, system info collection. Communicates over TCP to C2 servers. Continuously updated with new capabilities and obfuscation. Delivered primarily via malicious Office documents (XLS/DOC) with VBA macros that decrypt embedded PE payloads hidden in text boxes.

2. **ObliqueRAT** — C/C++-based implant discovered by Cisco Talos (Feb 2020). Reserved for hyper-targeted operations where stealth is critical. Capabilities: system info, drive enumeration, file search/exfiltration (ZIP compressed), command execution, file download/deletion, process listing/killing, reverse shell. Evolved delivery: initially embedded in maldocs, later hosted on compromised legitimate websites (e.g., iiaonline.in — Indian Industries Association). Hidden inside BMP image files using steganography.

3. **Custom downloaders/droppers** — Lightweight tools for quick deployment, containing limited capabilities compared to CrimsonRAT/ObliqueRAT.

**ANDROID ARSENAL:**

4. **CapraRAT** — Custom Android RAT with design similarities to CrimsonRAT (shared function names, commands, capabilities — documented by Trend Micro Jan 2022). Observed since 2017. Capabilities: GPS location, SMS read/send, contacts, call history, audio recording, camera, screen recording, file browsing/upload/deletion, process management. Delivered as trojanized apps: YouTube mimics, TikTok, gaming apps, weapons enthusiast apps, romance/honeytrap apps. SentinelOne documented 'CapraTube Remix' campaign (2024) targeting gamers and weapons enthusiasts with WebView-wrapped YouTube/CrazyGames apps.

5. **Modified AhMyth RAT** — Open-source Android RAT customized by Transparent Tribe. Distributed as fake Aarogya Setu COVID-19 tracking app and porn-themed apps. Enhanced with audio surveillance, SMS deletion, auto-download of contacts/messages/WhatsApp media. C2 configuration fetched from external URL (not hardcoded).

6. **StealthAgent** — Earlier Android spyware (2018) intercepting calls/messages, tracking location, stealing photos.

**DELIVERY METHODS:** - Spearphishing emails with malicious Office documents (VBA macros) — primary vector - Honeytrap social engineering (fake profiles of women, romance-themed lures) - Fake government documents (military notices, pay commission updates, COVID-19 tracking) - Fake conference materials (agenda documents for defense conferences) - Fake domains: studentsportal[.]live, 7thcpcupdates[.]info, clawsindia[.]com, sharingmymedia[.]com - USB worm propagation module built into CrimsonRAT - Malicious Android APKs distributed via WhatsApp groups and phishing links - Trojanized apps mimicking legitimate services (YouTube, TikTok, COVID tracking)

**INFRASTRUCTURE:** Cisco Talos identified ZainHosting (Lahore, Pakistan) as infrastructure provider — registered ~2,000 domains including malicious ones. Email address rupees001@gmail.com linked to both legitimate hosting business and Transparent Tribe infrastructure. Uses typo-squatted domains (geo-news[.]tv mimicking geo[.]tv) with shared SSL certificates across malicious infrastructure.

MITRE ATT&CK techniques used in TL-2026-0106

collection

T1005 Data from Local System; T1025 Data from Removable Media; T1056.001 Keylogging; T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture; T1125 Video Capture

defense-evasion

T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1053.005 Scheduled Task; T1059.005 Visual Basic; T1204.002 Malicious File

discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery

command-and-control

T1071.001 Web Protocols; T1102 Web Service; T1571 Non-Standard Port

lateral-movement

T1091 Replication Through Removable Media

persistence

T1547.001 Registry Run Keys / Startup Folder

credential-access

T1555.003 Credentials from Web Browsers

initial-access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service

resource-development

T1583.001 Domains; T1585.001 Social Media Accounts

Remediation for APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for

Patches

  • N/A — social engineering delivery, no specific CVEs

Immediate actions

  • Block known Transparent Tribe C2 domains: shareboxs.net, sharingmymedia.com, tryanotherhorse.com, viral91.xyz, geo-news.tv
  • Block known C2 IPs: 173.249.50.243, 173.212.206.227, 89.45.67.160, 212.8.240.221
  • Disable Office VBA macros via GPO for non-essential users
  • Block sideloaded Android APKs — enforce Google Play-only installation policy for military/government devices
  • Monitor for .NET processes with CrimsonRAT behavioral patterns (TCP C2 communication, keylogger module deployment)

Workarounds

  • Disable macro execution in Office documents from external sources
  • Block execution of .NET binaries from %TEMP% and %APPDATA% directories
  • Android: do not install APKs from untrusted sources, especially via WhatsApp links

Longer-term hardening

  • Implement email gateway sandboxing for Office document attachments
  • Deploy EDR with .NET assembly analysis for CrimsonRAT detection
  • Mobile Device Management (MDM) for government/military personnel — restrict app installation sources
  • User awareness training: honeytrap social engineering, fake government document lures
  • Network monitoring for TCP connections to known Transparent Tribe infrastructure patterns
  • Monitor USB device connections — CrimsonRAT includes USB worm module

Timeline of APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for

  • Transparent Tribe first observed by security researchers. Kaspersky traces activity back to 2013, initially targeting Indian military and government personnel with early variants of espionage tools. Source: https://securelist.com/transparent-tribe-part-2/98233/
  • Palo Alto Unit42 publishes link between 'ProjectM' (Pakistan-based actor) and Operation Transparent Tribe, establishing the Pakistan-nexus attribution. Source: https://unit42.paloaltonetworks.com/unit42-projectm-link-found-between-pakistani-actor-and-operation-transparent-tribe/
  • Earliest observed CapraRAT Android samples. Trend Micro identifies com.example.appcode.appcode package with public test certificate, suggesting early development phase. C2 hosted on android.viral91.xyz subdomain. Source: https://www.trendmicro.com/en_us/research/22/a/investigating-apt36-or-earth-karkaddans-attack-chain-and-malware.html
  • Amnesty International publishes report on Pakistani agencies using Transparent Tribe's CrimsonRAT against human rights activists in Pakistan, expanding known targeting beyond Indian government/military. Source: https://www.amnesty.org/en/documents/asa33/8366/2018/en/
  • Cisco Talos discovers ObliqueRAT, a C/C++-based implant attributed to Transparent Tribe. Reserved for hyper-targeted operations with stealth priority. Distributed via malicious documents. Source: https://blog.talosintelligence.com/obliquerat-hits-victims-via-maldocs/
  • Transparent Tribe distributes fake Aarogya Setu COVID-19 tracking app (modified AhMyth RAT) targeting Indian military via WhatsApp groups. Indian Army issues warning about Pakistani intelligence operatives distributing the fake app. Source: https://securelist.com/transparent-tribe-part-2/98233/
  • Team Cymru publishes comprehensive Transparent Tribe infrastructure mapping, documenting RDP certificate pattern 'WIN-P9NRMH5G6M8' across C2 servers. Source: https://team-cymru.com/blog/2021/07/02/transparent-tribe-apt-infrastructure-mapping-2/
  • Transparent Tribe begins targeting Indian educational institutions (universities, colleges) — first documented expansion beyond military/government. Cisco Talos identifies studentsportal[.]live, studentsportal[.]website domains and ZainHosting (Lahore) infrastructure. Source: https://blog.talosintelligence.com/transparent-tribe-targets-education/
  • Trend Micro publishes comprehensive Earth Karkaddan (APT36) analysis documenting full attack chain: spearphishing → macro → Crimson RAT, plus CapraRAT Android component with CrimsonRAT code similarities. Source: https://www.trendmicro.com/en_us/research/22/a/investigating-apt36-or-earth-karkaddans-attack-chain-and-malware.html
  • SentinelOne documents CapraTube Remix: updated CapraRAT APKs targeting gamers (CrazyGames), weapons enthusiasts (Forgotten Weapons YouTube), and TikTok users. Updated for Android 8.0+ compatibility. C2: shareboxs.net / 173.249.50.243:18582. Source: https://www.sentinelone.com/labs/capratube-remix-transparent-tribes-android-spyware-targeting-gamers-weapons-enthusiasts/
  • As of 2026-05-29, APT36/Transparent Tribe remains highly active and undisrupted, with CYFIRMA (Dec 2025) and The Hacker News (Jan 2026) documenting new weaponized-LNK/HTA campaigns deploying Crimson RAT, CapraRAT, ElizaRAT and DeskRAT against Indian government and academia. Bitdefender (Mar 2026) reports the group escalating to AI-generated "vibeware" implants in Nim/Zig/Crystal, plus CERT-In 2025 advisories, confirming ACTIVE status with no takedown.

Sources cited for APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for

Detection coverage for TL-2026-0106

As of 2026-02-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0106 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats