Transparent Tribe (APT36) AI-Assisted Vibeware Campaign — 14+ Malware Families Across 6+ C2 Channels

Transparent Tribe (APT36) AI-Assisted Vibeware Campaign (TL-2026-0189), also tracked as Operation Vibeware, is a high-severity advanced persistent threat campaign, first published 2026-03-07. It is attributed to APT36 (Pakistan) with high confidence, affects Indian Government Government Networks, maps to 35 MITRE ATT&CK techniques (T1005, T1008, T1027), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-0189

Threat ID
TL-2026-0189
Also known as
Operation Vibeware, Distributed Denial of Detection Campaign
Severity
HIGH
Status
MONITORING
Category
APT
First published
2026-03-07
Last reviewed
2026-03-07
Attribution
APT36
Attribution confidence
HIGH
Nation-state nexus
Pakistan
Motivation
ESPIONAGE
Target sectors
government, defense, diplomacy, military, aerospace, academia, startups, cybersecurity
Target regions
India, South Asia, Afghanistan, Global (Indian embassies)
Detection rules
9
Indicators of compromise
31

Malware and tooling in Transparent Tribe (APT36) AI-Assisted Vibeware Campaign

Malware and tooling: CreepDropper, CrystalShell, MAILCREEP, SHEETCREEP, SupaServ, Cobalt Strike, Havoc

Pakistan-nexus threat group APT36 (Transparent Tribe) has launched a sophisticated AI-assisted campaign deploying over 14 malware families written in uncommon languages (Nim, Zig, Crystal, Rust, Go) across 7 distinct C2 channels including Discord, Slack, Google Sheets, Supabase, and Firebase. Dubbed 'Vibeware' by Bitdefender researchers, the campaign targets Indian government, defense, diplomatic missions, and Afghan government entities using a Distributed Denial of Detection (DDoD) strategy that floods environments with disposable polyglot binaries.

How Transparent Tribe (APT36) AI-Assisted Vibeware Campaign works

Transparent Tribe (APT36), a Pakistan-aligned advanced persistent threat group, has adopted an AI-driven malware industrialization model that Bitdefender researchers term 'Vibeware.' Rather than pursuing technical sophistication, the group leverages AI coding assistants to mass-produce malware implants in uncommon programming languages — Nim, Zig, Crystal, Rust, and Go — to evade signature-based detection engines.

The campaign deploys 14+ distinct malware families organized into functional categories:

**Shellcode Loaders:** Warcode (Crystal-based Havoc C2 loader), NimShellcodeLoader (Nim-based Cobalt Strike wrapper using AES-CBC with SHA256 of password 'Pun7sh3r@123'), and ZigLoader (Zig shellcode loader with rolling XOR scheme, base key 0xAA).

**Infostealers:** SheetCreep (C# backdoor using Google Sheets for C2 with Base64+DES-ECB encryption), MailCreep (Go-based infostealer leveraging Microsoft Graph API), LuminousStealer (Rust-based file harvester exfiltrating .txt/.docx/.pdf/.png/.jpg/.xlsx/.pptx/.zip/.rar/.doc/.xls via Firebase and Google Drive), and LuminousCookies (Rust-based Chromium App-Bound Encryption bypass for credential theft).

**Backdoors:** SupaServ (Rust backdoor with Supabase primary and Firebase fallback C2), CrystalShell (Crystal cross-platform backdoor for Windows/Linux/macOS using Discord and Slack C2), ZigShell (Zig-based Slack C2 agent), CrystalFile (Crystal command interpreter monitoring local directories), and Gate Sentinel Beacon (modified open-source C2 framework).

**Support Tools:** CreepDropper (.NET dropper delivering SheetCreep and MailCreep), BackupSpy (Rust filesystem and external media monitoring utility).

The attack chain initiates through spear-phishing emails containing ZIP/ISO archives with LNK shortcuts masquerading as legitimate documents (e.g., resumes, government correspondence). Opening the LNK triggers PowerShell fileless execution via mshta.exe, leading to primary backdoor deployment. The group uses LinkedIn to identify and profile high-value targets in Indian military and diplomatic domains.

C2 infrastructure leverages 7 distinct legitimate cloud services: Discord (hardcoded channel IDs with token progression from hardcoded to Firebase to Supabase), Slack (primary for ZigShell), Google Sheets (SheetCreep hub with columns: unenc_requests, unenc_outputs, unenc_heartbeats, unenc_systems), Supabase (PostgreSQL-based), Firebase Realtime Database, Google Drive (OAuth-authenticated exfiltration), and Microsoft Graph API (MailCreep exfiltration). This multi-channel approach provides operational redundancy through T1008 Fallback Channels.

The 'malware-a-day' production cadence generates daily variants, with compilation timestamps spanning October 2025 through February 2026. Build environment forensics reveal a Rust development path C:\Users\kumar\.cargo\ and the recurring username 'Nightmare' across attacker systems. Unicode emojis embedded in Rust binaries and verbose AI-style comments in source code confirm generative AI tool usage.

Bitdefender characterizes this as a 'Distributed Denial of Detection (DDoD)' strategy — flooding defensive engines with volume and linguistic diversity rather than bypassing them through advanced evasion. While the resulting malware is often unstable and riddled with logical errors, the sheer volume challenges SOC teams and signature-based detection engines.

Payload hosting infrastructure uses domains impersonating Indian High Commission services: hciaccounts.in, hcisupport.in, hcidelhi.in, hcidoc.in, and coadelhi.in. Additional C2 infrastructure includes slackin.online (abusing Azure Front Door) and multiple Firebase Realtime Database instances.

---

**Revalidated on 2026-03-12**

Revalidation confirms this threat remains highly active with significant escalation across targeting scope, malware arsenal, and operational tempo. Since initial publication, several major developments warrant updating the intelligence record.

**Expanded Targeting Beyond Government/Defense:** Acronis TRU documented a strategic pivot in January 2026 where APT36 expanded beyond traditional government/defense targets to India's startup ecosystem, specifically OSINT and cybersecurity firms, using ISO-delivered Crimson RAT with personalized startup-founder-themed lure material. Indian embassies in multiple foreign countries and Afghan government entities have also been confirmed as active targets via LinkedIn-based reconnaissance.

**Operation Sindoor (May 2025):** Seqrite Labs documented a coordinated cyber siege where APT36 collaborated with 35+ hacktivist outfits, producing 650+ cyber incidents between May 7-10, 2025. The operation targeted Indian critical infrastructure including telecom providers (Jio, BSNL), healthcare institutions (AIIMS, Apollo Hospitals), defense entities (MoD, Army, Navy, DRDO), and state education portals. This represents APT36's most significant known coordination with non-state hacktivist actors and signals convergence of espionage and ideological warfare.

**Malware Arsenal Growth:** The observable malware family count has grown from the initial 14 to 18+, with newly documented families including GETA RAT (.NET-based RAT linked to SideCopy cluster), Ares RAT (Python-based, Go-delivered Linux RAT), DeskRAT (WebSocket-based C2 with real-time host telemetry), and Poseidon (Linux Mythic framework agent with keylogging, screen capture, and file exfiltration). The Aryaka C2 tradecraft report (February 2026) provided the most comprehensive network-level analysis to date, documenting fixed-size encrypted command packets, regular beacon intervals, and long-lived outbound connections across non-standard ports.

**Pahalgam Terror Attack Exploitation:** Seqrite Labs revealed that APT36 pre-compiled three RAT payloads on April 21, 2025 — one day before the Pahalgam terror attack — then weaponized the tragedy as phishing lure material with fake domains impersonating Jammu & Kashmir Police (jkpolice.gov.in.kashmirattack.exposed) and Indian Air Force, delivering Crimson RAT via PPAM macros.

**Advanced LNK Tradecraft:** CYFIRMA and PolySwarm documented evolution of APT36's LNK-based delivery mechanism: oversized 2MB+ shortcut files embedding complete PDF documents, fileless execution via mshta.exe, layered in-memory decryption, and antivirus-aware persistence mechanisms that adapt behavior based on the security product environment detected on the target host.

**Linux Targeting Expansion:** APT36 is increasingly targeting Linux environments due to Indian government adoption of Debian-based BOSS OS and the introduction of Maya OS, deploying Poseidon and Ares RAT via Go-based downloaders and shell scripts.

**Government Response:** CERT-In and Chandigarh Police issued renewed warnings about APT36 activity. DSCI published a formal threat advisory in October 2025. An academic paper on arXiv documented the Operation Sindoor malware campaign analysis and proposed detection frameworks.

MITRE ATT&CK techniques used in TL-2026-0189

collection

T1005 Data from Local System; T1056 Input Capture; T1115 Clipboard Data; T1530 Data from Cloud Storage; T1560 Archive Collected Data

command-and-control

T1008 Fallback Channels; T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1132 Data Encoding; T1573 Encrypted Channel

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1564 Hide Artifacts; T1620 Reflective Code Loading

discovery

T1033 System Owner/User Discovery; T1087 Account Discovery

exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1106 Native API; T1129 Shared Modules; T1204 User Execution

credential-access

T1187 Forced Authentication

persistence

T1547 Boot or Logon Autostart Execution

initial-access

T1566 Phishing

resource-development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in Transparent Tribe (APT36) AI-Assisted Vibeware Campaign

  • Indian Government — Government Networks
    Vulnerable versions: All
  • Indian Ministry of External Affairs — Embassy Systems
    Vulnerable versions: All
  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2019; Server 2022
  • Linux — Various Distributions
    Vulnerable versions: All
  • Apple — macOS
    Vulnerable versions: All

Remediation for Transparent Tribe (APT36) AI-Assisted Vibeware Campaign

Immediate actions

  • Block payload hosting domains at perimeter: hciaccounts.in, hcisupport.in, hcidelhi.in, hcidoc.in, coadelhi.in
  • Block C2 IP 23.152.0.81 and 15.207.85.170 at firewall
  • Monitor for unsigned binaries in %APPDATA% and C:\Users\Public\ directories
  • Implement granular monitoring for Discord, Slack, and Google Sheets traffic from unverified binaries
  • Hunt for scheduled tasks named MicrosoftEdgesUpdatesTasksMachineUAs-Task, DateAndTimeService, LuminousBackupService

Workarounds

  • Block LNK file execution from ZIP/ISO archives via Group Policy
  • Restrict mshta.exe and PowerShell execution for non-admin users
  • Disable macro execution in Microsoft Office documents
  • Implement network segmentation to limit lateral movement from compromised endpoints

Longer-term hardening

  • Deploy behavioral detection focused on process behavior rather than file signatures
  • Implement EDR/XDR with dynamic attack surface reduction
  • Establish mature SOC/MDR operations for polyglot binary analysis
  • Monitor for unusual use of Nim, Zig, Crystal, and Rust compiled binaries in enterprise environments
  • Implement application whitelisting to prevent execution of unsigned binaries from user-writable directories

Timeline of Transparent Tribe (APT36) AI-Assisted Vibeware Campaign

Showing the 20 most recent tracked events.

  • Transparent Tribe targets Indian government entities with weaponized desktop shortcuts disguised as PDF documents, deploying shell script-based infection chains targeting Linux environments running BOSS OS and Maya OS [Source: https://thehackernews.com/2025/08/transparent-tribe-targets-indian-govt.html]
  • DSCI (Data Security Council of India) issues formal threat advisory covering APT36 targeting of Indian defense and aerospace sectors with cross-platform malware [Source: https://www.dsci.in/files/content/advisory/2025/Threat-Advisory-October-2025-v2.pdf]
  • Sekoia and QiAnXin XLab document APT36''s deployment of DeskRAT with WebSocket-based C2, real-time host telemetry collection, and detailed system diagnostics exfiltration [Source: https://thehackernews.com/2026/02/apt36-and-sidecopy-launch-cross.html]
  • MailCreep victim sample compiled (timestamp: 2025-10-28 09:58:46), marking early campaign development
  • CYFIRMA publishes multi-stage LNK malware campaign analysis — oversized 2MB+ LNK files embedding complete PDF documents, fileless mshta.exe execution, layered in-memory decryption, and AV-aware persistence mechanisms across diverse Indian security environments [Source: https://www.cyfirma.com/research/apt36-multi-stage-lnk-malware-campaign-targeting-indian-government-entities/]
  • Team Cymru publishes APT36 infrastructure mapping identifying C2 hosting patterns and Pi NET LLC VPS usage
  • CrystalShell earliest variants compiled, demonstrating cross-platform backdoor capability across Windows, Linux, macOS
  • Cyberwarzone publishes analysis of APT36 weaponized shortcuts with adaptive persistence targeting Indian government entities, confirming evolution of LNK-based tradecraft [Source: https://cyberwarzone.com/2026/01/04/transparent-tribe-apt36-weaponized-shortcuts-and-adaptive-persistence-target-indian-government-entities/]
  • LuminousStealer and LuminousCookies compiled, expanding Rust-based infostealer arsenal with Firebase/Google Drive exfiltration
  • BackupSpy compiled, adding filesystem and external media monitoring capability to the campaign toolkit
  • Acronis Threat Research Unit uncovers APT36 strategic pivot to India''s startup ecosystem — ISO-delivered Crimson RAT using startup-founder-themed lure material (MeetBisht.iso) targeting OSINT and cybersecurity firms [Source: https://www.acronis.com/en/tru/posts/new-year-new-sector-transparent-tribe-targets-indias-startup-ecosystem/]
  • Updated LuminousCookies variant compiled (2026-01-27 11:46:05), targeting Chromium App-Bound Encryption bypass
  • Zscaler ThreatLabz publishes research on SHEETCREEP, FIREPOWER, and MAILCREEP targeting Indian government entities
  • ZigShell compiled, introducing Zig-based Slack C2 agent to the polyglot malware fleet
  • Aryaka publishes comprehensive C2 tradecraft report detailing APT36 and SideCopy cross-platform RAT campaigns — GETA RAT, Ares RAT, and DeskRAT with fixed-size encrypted command packets, regular beacon intervals, and WebSocket C2 across Windows and Linux [Source: https://www.aryaka.com/reports-and-guides/transparent-tribe-apt36-cc-network-tradecraft-report/]
  • Reports emerge of APT36 and SideCopy launching cross-platform RAT campaigns against Indian entities
  • Computer Weekly, SC Media, GBHackers, and CyberSecurityNews amplify the Bitdefender vibeware findings, establishing ''Distributed Denial of Detection'' as a recognized adversary strategy in mainstream cybersecurity discourse [Source: https://www.computerweekly.com/news/366639830/APT36-unleashes-AI-generated-vibeware-to-flood-targets]
  • Bitdefender publishes comprehensive research 'APT36: A Nightmare of Vibeware' detailing 14+ AI-assisted malware families across 7 C2 channels
  • Hackread reports APT36 flooding Indian government networks with AI-made vibeware, confirming targeting of Indian embassies in foreign countries and Afghan government entities via LinkedIn-based reconnaissance [Source: https://hackread.com/pakistan-apt36-indian-govt-networks-ai-vibeware/]
  • As of 2026-05-29, APT36 (Transparent Tribe) remains an actively operating Pakistan-nexus espionage actor and the Vibeware AI-malware campaign against Indian government/diplomatic targets shows no disruption, takedown, or successor. No CVE applies (KEV/patch N/A); concrete compile/IOC activity is documented through Feb-Mar 2026 with no fresh Apr-May disclosures, so MONITORING fits an ongoing campaign by a live actor.

Sources cited for Transparent Tribe (APT36) AI-Assisted Vibeware Campaign

Threats related to Transparent Tribe (APT36) AI-Assisted Vibeware Campaign

Detection coverage for TL-2026-0189

As of 2026-03-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0189 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats