Transparent Tribe (APT36) AI-Assisted Vibeware Campaign — 14+ Malware Families Across 6+ C2 Channels — Threadlinqs Intelligence
As of 2026-05-30, Transparent Tribe (APT36) AI-Assisted Vibeware Campaign — 14+ Malware Families Across 6+ C2 Channels is a high-severity apt threat attributed to APT36 (Pakistan), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-0189 · Severity: HIGH · Status: MONITORING · Category: APT
Attribution: APT36 · Pakistan · ESPIONAGE
Pakistan-nexus threat group APT36 (Transparent Tribe) has launched a sophisticated AI-assisted campaign deploying over 14 malware families written in uncommon languages (Nim, Zig, Crystal, Rust, Go)
Transparent Tribe (APT36), a Pakistan-aligned advanced persistent threat group, has adopted an AI-driven malware industrialization model that Bitdefender researchers term 'Vibeware.' Rather than pursuing technical sophistication, the group leverages AI coding assistants to mass-produce malware implants in uncommon programming languages — Nim, Zig, Crystal, Rust, and Go — to evade signature-based detection engines.
The campaign deploys 14+ distinct malware families organized into functional categories:
**Shellcode Loaders:** Warcode (Crystal-based Havoc C2 loader), NimShellcodeLoader (Nim-based Cobalt Strike wrapper using AES-CBC with SHA256 of password 'Pun7sh3r@123'), and ZigLoader (Zig shellcode loader with rolling XOR scheme, base key 0xAA).
**Infostealers:** SheetCreep (C# backdoor using Google Sheets for C2 with Base64+DES-ECB encryption), MailCreep (Go-based infostealer leveraging Microsoft Graph API), LuminousStealer (Rust-based file harvester exfiltrating .txt/.docx/.pdf/.png/.jpg/.xlsx/.pptx/.zip/.rar/.doc/.xls via Firebase and Google Drive), and LuminousCookies (Rust-based Chromium App-Bound Encryption bypass for credential theft).
**Backdoors:** SupaServ (Rust backdoor with Supabase primary and Firebase fallback C2), CrystalShell (Crystal cross-platform backdoor for Windows/Linux/macOS using Discord and Slack C2), ZigShell (Zig-based Slack C2 agent), CrystalFile (Crystal command interpreter monitoring local directories), and Gate Sentinel Beacon (modified open-source C2 framework).
**Support Tools:** CreepDropper (.NET dropper delivering SheetCreep and MailCreep), BackupSpy (Rust filesystem and external media monitoring utility).
The attack chain initiates through spear-phishing emails containing ZIP/ISO archives with LNK shortcuts masquerading as legitimate documents (e.g., resumes, government correspondence). Opening the LNK triggers PowerShell fileless execution via mshta.exe, leading to primary backdoor deployment. The group uses LinkedIn to identify and profile high-value targets in Indian military and diplomatic domains.
C2 infrastructure leverages 7 distinct legitimate cloud services: Discord (hardcoded channel IDs with token progression from hardcoded to Firebase to Supabase), Slack (primary for ZigShell), Google Sheets (SheetCreep hub with columns: unenc_requests, unenc_outputs, unenc_heartbeats, unenc_systems), Supabase (PostgreSQL-based), Firebase Realtime Database, Google Drive (OAuth-authenticated exfiltration), and Microsoft Graph API (MailCreep exfiltration). This multi-channel approach provides operational redundancy through T1008 Fallback Channels.
The 'malware-a-day' production cadence generates daily variants, with compilation timestamps spanning October 2025 through February 2026. Build environment forensics reveal a Rust development path C:\Users\kumar\.cargo\ and the recurring username 'Nightmare' across attacker systems. Unicode emojis embedded in Rust binaries and verbose AI-style comments in source code confirm generative AI tool usage.
Bitdefender characterizes this as a 'Distributed Denial of Detection (DDoD)' strategy — flooding defensive engines with volume and linguistic diversity rather than bypassing them through advanced evasion. While the resulting malware is often unstable and riddled with logical errors, the sheer volume challenges SOC teams and signature-based detection engines.
Payload hosting infrastructure uses domains impersonating Indian High Commission services: hciaccounts.in, hcisupport.in, hcidelhi.in, hcidoc.in, and coadelhi.in. Additional C2 infrastructure includes slackin.online (abusing Azure Front Door) and multiple Firebase Realtime Database instances.
---
**Revalidated on 2026-03-12**
Revalidation confirms this threat remains highly active with significant escalation across targeting scope, malware arsenal, and operational tempo. Since initial publication, several major developments warrant updating the intelligence record.
**Expanded Targeting Beyon
Target sectors: government, defense, diplomacy, military, aerospace, academia, startups, cybersecurity
Target regions: India, South Asia, Afghanistan, Global (Indian embassies)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1589, T1583, T1583, T1585, T1587, T1588, T1608, T1566, T1059, T1059