APT36 "Vibeware" Campaign: AI-Assisted Malware Industrialization Targets Indian and Afghan Government — Threadlinqs Intelligence
As of 2026-03-05, APT36 "Vibeware" Campaign: AI-Assisted Malware Industrialization Targets Indian and Afghan Government is a high-severity apt threat attributed to APT36 (Pakistan), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-2123 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: APT36 · Pakistan · ESPIONAGE
Bitdefender documents APT36 (Transparent Tribe), a Pakistan-aligned threat actor, operating an AI-assisted malware development pipeline codenamed "Vibeware" that produces new implants at a near-daily
Bitdefender's "APT36: A Nightmare of Vibeware" (published 2026-03-05) documents an AI-assisted malware development model attributed with medium confidence to APT36 (Transparent Tribe), a Pakistan-aligned espionage actor active since at least 2013. Rather than investing in a small number of polished tools, the actor uses LLMs and AI-integrated development tooling to rewrite similar malicious logic across niche and mainstream programming languages -- Nim, Zig, Crystal, Rust, Go, and .NET -- producing a stream of functionally sufficient but frequently buggy implants intended to reset detection-engine baselines with every recompilation in a different language runtime.
At least 14 distinct malware families were identified: Warcode (Crystal, a Havoc-framework loader previously seen in earlier APT36 campaigns and staged as C:\Users\Public\AccountPictures\warcode.exe), NimShellcodeLoader (Nim), CreepDropper (.NET), MailCreep (Go, a browser-credential stealer abusing the Microsoft Graph API, shipped with a template placeholder in place of a real C2 URL that leaves it unable to exfiltrate anything -- direct evidence of unreviewed AI-generated code), SheetCreep (C#, a bidirectional Google Sheets C2 hub using DES-ECB-encrypted cell data and a reverse-byte-ordered PE payload disguised as an image file, ds.png), SupaServ (Rust, Supabase-primary/Firebase-backup C2), LuminousStealer (Rust, stages stolen data in a local SQLite database before exfiltrating file contents via Google Drive and metadata via Firebase), CrystalShell and ZigShell (Crystal/Zig, near-identical Base64-command-prefix bots for Discord and Slack respectively, both requiring Discord User ID verification and both containing broken "online status" and master-election logic), CrystalFile (Crystal, polls C:\Users\Public\AccountPictures\input.txt for commands and never cleans up its temp output), LuminousCookies (Rust, a Chrome App-Bound Encryption bypass), BackupSpy (Rust, stages collected files under C:\Users\Public\systemTemp), ZigLoader (Zig), and Gate Sentinel Beacon (a Go server / C client C2 pair modeled on the open-source GateSentinel project).
Initial access is via spearphishing email carrying .LNK files inside ZIP or ISO containers, or PDF lures with a "Download Document" button that redirects through attacker-controlled sites to an external archive. Execution relies on fileless PowerShell and process injection (VirtualAllocEx/WriteProcessMemory/CreateRemoteThread); persistence uses Windows Scheduled Tasks under names such as DateAndTimeService, personalServiceTask, and MicrosoftEdgesUpdatesTasksMachine*, plus modified .LNK shortcuts targeting Chrome, Edge, and Brave. LuminousCookies defeats Chrome's App-Bound Encryption (introduced in Chrome 127) by spawning a suspended browser process and using LoadLibrary injection to load a modified decryptor DLL that masquerades as a legitimate browser component -- a technique adapted from the public xaitax/Chrome-App-Bound-Encryption-Decryption proof of concept, though the researchers note the LoadLibrary-injection approach cannot pass the pipe-name argument the standard ABE decryptor expects via DllMain, forcing a hard-coded workaround.
Collection targets .txt, .docx, .pdf, .png, .jpg, .xlsx, .pptx, .zip, .rar, .doc, and .xls files via recursive directory scanning, plus PowerShell-driven screenshot and audio capture. Exfiltration and C2 both route through abused legitimate cloud services -- Discord, Slack, Google Sheets, Supabase, Firebase, and Google Drive -- with tmpfiles.org used for auxiliary tool hosting and slackin.online (fronted by Azure Front Door) as a Slack-C2-adjacent domain. Attribution to APT36 rests on Warcode's reuse of a Havoc-framework loader previously tied to the group and a recurring "Nightmare" persona across actor infrastructure. Primary targets are Indian government bodies and embassies; secondary targets are the Afghan government and private businesses, with attacker interest concentrated on army perso
Target sectors: government administration, defense, diplomatic, military, private-sector
Target regions: South Asia, india, afghanistan
Timeline
- SheetCreep sample compiled (timestamp 2025-10-28 09:58:46), the earliest dated Vibeware artifact identified by Bitdefender researchers.
- Initial CrystalShell variants observed with hardcoded Discord bot tokens, the earliest identified use of Discord as a Vibeware C2 channel (exact day within December 2025 not specified in source).
- CrystalShell/ZigShell Discord and Slack C2 messaging traffic begins, continuing through the report's publication.
- CrystalShell Slack variant compiled, extending the Discord-based bot's protocol to Slack.
- LuminousStealer and LuminousCookies samples compiled, introducing Firebase/Google Drive exfiltration and the Chrome App-Bound Encryption bypass to the Vibeware toolset.
- Further CrystalShell activity observed against Indian government targets.
- Updated LuminousCookies injector sample compiled.
- New ZigShell variants compiled, continuing the actor's near-daily recompilation cadence.
- Bitdefender publishes "APT36: A Nightmare of Vibeware," the first public documentation of the AI-assisted Vibeware development pipeline and its 14+ malware families.
- Cloud Security Alliance publishes a companion technical report, "AI-Assisted Malware Industrialization: The Vibeware Threat Model."
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566.001, T1204.002, T1059.001, T1059.003, T1053.005, T1547.009, T1055, T1140, T1036, T1027