APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform Espionage — Threadlinqs Intelligence
As of 2026-05-30, APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform Espionage is a high-severity apt threat attributed to APT36 (Pakistan), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0106 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: APT36 · Pakistan · ESPIONAGE
APT36/Transparent Tribe (Pakistan-nexus, ISI-linked) deploys Crimson RAT (.NET) and CapraRAT (Android) for persistent espionage against Indian military, government, defense, diplomatic, and education
APT36, also known as Transparent Tribe, Earth Karkaddan, Operation C-Major, PROJECTM, and Mythic Leopard, is a Pakistan-nexus advanced persistent threat group active since at least 2013. The group is assessed with high confidence to be linked to Pakistan's Inter-Services Intelligence (ISI) directorate, conducting persistent cyber-espionage operations primarily against Indian military and government targets within the India-Pakistan geopolitical context.
**V1 CORRECTION: The v1 seed data claimed 'Indian startup ecosystem' targeting. This is FABRICATED. All verified primary sources (Cisco Talos, Trend Micro, Kaspersky, SentinelOne, Proofpoint) consistently document targeting of Indian military, government, defense, diplomatic, and education sectors. The group expanded to education (universities/colleges) in late 2021 (Cisco Talos), NOT startups. No evidence of specific startup ecosystem targeting exists in any primary source.**
**WINDOWS ARSENAL:**
1. **Crimson RAT** — The group's primary implant since at least 2016. Written in .NET with minimal obfuscation (Trend Micro notes this may indicate limited funding). Capabilities: file enumeration, process listing, screenshot capture, keylogging module, USB worm module, browser credential theft, arbitrary command execution, file exfiltration/deletion, drive listing, system info collection. Communicates over TCP to C2 servers. Continuously updated with new capabilities and obfuscation. Delivered primarily via malicious Office documents (XLS/DOC) with VBA macros that decrypt embedded PE payloads hidden in text boxes.
2. **ObliqueRAT** — C/C++-based implant discovered by Cisco Talos (Feb 2020). Reserved for hyper-targeted operations where stealth is critical. Capabilities: system info, drive enumeration, file search/exfiltration (ZIP compressed), command execution, file download/deletion, process listing/killing, reverse shell. Evolved delivery: initially embedded in maldocs, later hosted on compromised legitimate websites (e.g., iiaonline.in — Indian Industries Association). Hidden inside BMP image files using steganography.
3. **Custom downloaders/droppers** — Lightweight tools for quick deployment, containing limited capabilities compared to CrimsonRAT/ObliqueRAT.
**ANDROID ARSENAL:**
4. **CapraRAT** — Custom Android RAT with design similarities to CrimsonRAT (shared function names, commands, capabilities — documented by Trend Micro Jan 2022). Observed since 2017. Capabilities: GPS location, SMS read/send, contacts, call history, audio recording, camera, screen recording, file browsing/upload/deletion, process management. Delivered as trojanized apps: YouTube mimics, TikTok, gaming apps, weapons enthusiast apps, romance/honeytrap apps. SentinelOne documented 'CapraTube Remix' campaign (2024) targeting gamers and weapons enthusiasts with WebView-wrapped YouTube/CrazyGames apps.
5. **Modified AhMyth RAT** — Open-source Android RAT customized by Transparent Tribe. Distributed as fake Aarogya Setu COVID-19 tracking app and porn-themed apps. Enhanced with audio surveillance, SMS deletion, auto-download of contacts/messages/WhatsApp media. C2 configuration fetched from external URL (not hardcoded).
6. **StealthAgent** — Earlier Android spyware (2018) intercepting calls/messages, tracking location, stealing photos.
**DELIVERY METHODS:**
- Spearphishing emails with malicious Office documents (VBA macros) — primary vector
- Honeytrap social engineering (fake profiles of women, romance-themed lures)
- Fake government documents (military notices, pay commission updates, COVID-19 tracking)
- Fake conference materials (agenda documents for defense conferences)
- Fake domains: studentsportal[.]live, 7thcpcupdates[.]info, clawsindia[.]com, sharingmymedia[.]com
- USB worm propagation module built into CrimsonRAT
- Malicious Android APKs distributed via WhatsApp groups and phishing links
- Trojanized apps mimicking legitimate services (YouTube, TikTok, COVID tracking)
**INFRASTRUCTURE:**
Ci
Target sectors: Military, Government, Defense, Diplomatic, Education
Target regions: India, South Asia
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566.001, T1566.002, T1204.002, T1059.005, T1547.001, T1053.005, T1027.003, T1036.005, T1056.001, T1555.003