APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign

A threat actor with ties to Pakistan has been seen launching spear-phishing operations against Indian government organizations in an attempt to spread DeskRAT, a Golang-based malware.

Sekoia saw the activity in August and September of 2025, and it has been linked to Transparent Tribe (also known as APT36), a state-sponsored hacker collective that has been active since at least 2013. Additionally, it expands on a previous campaign that CYFIRMA revealed in August 2025.

Phishing emails with a ZIP file attachment or, occasionally, a link to an archive stored on reputable cloud services like Google Drive are part of the attack chains. The ZIP package contains malicious desktop file embedding commands that, when run alongside the main payload, cause Mozilla Firefox to display a phony PDF (“CDS_Directive_Armed_Forces.pdf”).

The external server “modgovindia[.]com” is used to extract and run both artifacts. Similar to the previous campaign, the remote access trojan may establish command-and-control (C2) over WebSockets, and the campaign is intended to target BOSS (Bharat Operating System Solutions) Linux computers read more about APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *