Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT

A Pakistani threat actor has been seen using remote access trojans such as Xeno RAT, Spark RAT, and CurlBack RAT, a family of malware that has not yet been identified, to attack different sectors in India.

The hacking crew’s targeting footprint was extended outside the government, defense, maritime, and academic sectors when SEQRITE discovered the activity in December 2024. It targeted Indian companies under the ministries of railway, oil and gas, and external affairs.

One significant change in recent campaigns is the use of Microsoft Installer (MSI) packages as the main staging technique instead of HTML Application (HTA) files, according to security researcher Sathwik Ram Prakki.

SideCopy is thought to be a Transparent Tribe (also known as APT36) sub-cluster that has been operational since at least 2019 read more about Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *