# APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform Espionage

> APT36/Transparent Tribe (Pakistan-nexus, ISI-linked) deploys Crimson RAT (.NET) and CapraRAT (Android) for persistent espionage against Indian military, government, defense, diplomatic, and education sectors since 2013. Multi-platform arsenal spanning Windows (CrimsonRAT, ObliqueRAT), Android (CapraRAT, modified AhMyth), and USB worms.

- **Published:** 2026-02-16T10:55:41Z
- **Last reviewed:** 2026-02-16T10:55:41Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0106
- **ID:** TL-2026-0106
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** APT36 (Pakistan)
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

APT36, also known as Transparent Tribe, Earth Karkaddan, Operation C-Major, PROJECTM, and Mythic Leopard, is a Pakistan-nexus advanced persistent threat group active since at least 2013. The group is assessed with high confidence to be linked to Pakistan's Inter-Services Intelligence (ISI) directorate, conducting persistent cyber-espionage operations primarily against Indian military and government targets within the India-Pakistan geopolitical context.

**V1 CORRECTION: The v1 seed data claimed 'Indian startup ecosystem' targeting. This is FABRICATED. All verified primary sources (Cisco Talos, Trend Micro, Kaspersky, SentinelOne, Proofpoint) consistently document targeting of Indian military, government, defense, diplomatic, and education sectors. The group expanded to education (universities/colleges) in late 2021 (Cisco Talos), NOT startups. No evidence of specific startup ecosystem targeting exists in any primary source.**

**WINDOWS ARSENAL:**

1. **Crimson RAT** — The group's primary implant since at least 2016. Written in .NET with minimal obfuscation (Trend Micro notes this may indicate limited funding). Capabilities: file enumeration, process listing, screenshot capture, keylogging module, USB worm module, browser credential theft, arbitrary command execution, file exfiltration/deletion, drive listing, system info collection. Communicates over TCP to C2 servers. Continuously updated with new capabilities and obfuscation. Delivered primarily via malicious Office documents (XLS/DOC) with VBA macros that decrypt embedded PE payloads hidden in text boxes.

2. **ObliqueRAT** — C/C++-based implant discovered by Cisco Talos (Feb 2020). Reserved for hyper-targeted operations where stealth is critical. Capabilities: system info, drive enumeration, file search/exfiltration (ZIP compressed), command execution, file download/deletion, process listing/killing, reverse shell. Evolved delivery: initially embedded in maldocs, later hosted on compromised legitimate websites (e.g., iiaonline.in — Indian Industries Association). Hidden inside BMP image files using steganography.

3. **Custom downloaders/droppers** — Lightweight tools for quick deployment, containing limited capabilities compared to CrimsonRAT/ObliqueRAT.

**ANDROID ARSENAL:**

4. **CapraRAT** — Custom Android RAT with design similarities to CrimsonRAT (shared function names, commands, capabilities — documented by Trend Micro Jan 2022). Observed since 2017. Capabilities: GPS location, SMS read/send, contacts, call history, audio recording, camera, screen recording, file browsing/upload/deletion, process management. Delivered as trojanized apps: YouTube mimics, TikTok, gaming apps, weapons enthusiast apps, romance/honeytrap apps. SentinelOne documented 'CapraTube Remix' campaign (2024) targeting gamers and weapons enthusiasts with WebView-wrapped YouTube/CrazyGames apps.

5. **Modified AhMyth RAT** — Open-source Android RAT customized by Transparent Tribe. Distributed as fake Aarogya Setu COVID-19 tracking app and porn-themed apps. Enhanced with audio surveillance, SMS deletion, auto-download of contacts/messages/WhatsApp media. C2 configuration fetched from external URL (not hardcoded).

6. **StealthAgent** — Earlier Android spyware (2018) intercepting calls/messages, tracking location, stealing photos.

**DELIVERY METHODS:**
- Spearphishing emails with malicious Office documents (VBA macros) — primary vector
- Honeytrap social engineering (fake profiles of women, romance-themed lures)
- Fake government documents (military notices, pay commission updates, COVID-19 tracking)
- Fake conference materials (agenda documents for defense conferences)
- Fake domains: studentsportal[.]live, 7thcpcupdates[.]info, clawsindia[.]com, sharingmymedia[.]com
- USB worm propagation module built into CrimsonRAT
- Malicious Android APKs distributed via WhatsApp groups and phishing links
- Trojanized apps mimicking legitimate services (YouTube, TikTok, COVID tracking)

**INFRASTRUCTURE:**
Cisco Talos identified ZainHosting (Lahore, Pakistan) as infrastructure provider — registered ~2,000 domains including malicious ones. Email address rupees001@gmail.com linked to both legitimate hosting business and Transparent Tribe infrastructure. Uses typo-squatted domains (geo-news[.]tv mimicking geo[.]tv) with shared SSL certificates across malicious infrastructure.

## MITRE ATT&CK

- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1059.005 Visual Basic
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task
- T1027.003 Steganography
- T1036.005 Match Legitimate Resource Name or Location
- T1056.001 Keylogging
- T1555.003 Credentials from Web Browsers
- T1083 File and Directory Discovery
- T1057 Process Discovery
- T1082 System Information Discovery
- T1113 Screen Capture
- T1005 Data from Local System
- T1025 Data from Removable Media
- T1123 Audio Capture
- T1125 Video Capture
- T1091 Replication Through Removable Media
- T1071.001 Web Protocols
- T1571 Non-Standard Port
- T1041 Exfiltration Over C2 Channel
- T1102 Web Service
- T1566.003 Spearphishing via Service
- T1070.004 File Deletion
- T1115 Clipboard Data
- T1120 Peripheral Device Discovery
- T1583.001 Domains
- T1585.001 Social Media Accounts

## Sources

- [Cisco Talos — Transparent Tribe Targets Education Sector](https://blog.talosintelligence.com/transparent-tribe-targets-education/)
- [Cisco Talos — Transparent Tribe APT Expands Windows Malware Arsenal](https://blog.talosintelligence.com/transparent-tribe-infra-and-targeting/)
- [Trend Micro — Earth Karkaddan (APT36) Attack Chain and Malware Arsenal](https://www.trendmicro.com/en_us/research/22/a/investigating-apt36-or-earth-karkaddans-attack-chain-and-malware.html)
- [Kaspersky — Transparent Tribe Evolution Part 2 (Android RAT + ObliqueRAT)](https://securelist.com/transparent-tribe-part-2/98233/)
- [SentinelOne — CapraTube Remix (CapraRAT Gamers/Weapons Targeting)](https://www.sentinelone.com/labs/capratube-remix-transparent-tribes-android-spyware-targeting-gamers-weapons-enthusiasts/)
- [Amnesty International — Pakistan Digital Surveillance (CrimsonRAT vs Human Rights)](https://www.amnesty.org/en/documents/asa33/8366/2018/en/)
- [Team Cymru — Transparent Tribe Infrastructure Mapping](https://team-cymru.com/blog/2021/07/02/transparent-tribe-apt-infrastructure-mapping-2/)
- [Palo Alto Unit42 — ProjectM Link to Transparent Tribe](https://unit42.paloaltonetworks.com/unit42-projectm-link-found-between-pakistani-actor-and-operation-transparent-tribe/)
- [Cisco Talos — ObliqueRAT Hits Victims via Maldocs](https://blog.talosintelligence.com/obliquerat-hits-victims-via-maldocs/)
- [K7 Computing — Transparent Tribe Targets Educational Institution](https://labs.k7computing.com/index.php/transparent-tribe-targets-educational-institution/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0106
