A hacker collective with contacts outside of Pakistan has been discovered using a modified version of the remote access trojan (RAT) known as DRAT to target government agencies in India.
Recorded Future’s Insikt Group has attributed the activity to a threat actor identified as TAG-140, which it claims overlaps with SideCopy, an adversarial collective evaluated as an operational sub-cluster within Transparent Tribe (also known as APT-C-56, APT36, Datebug, Earth Karkaddan, Mythic Leopard, Operation C-Major, and ProjectM).
In an analysis released this month, the Mastercard-owned company claimed that TAG-140 has continuously shown iterative development and variety in its malware arsenal and delivery methods.
This most recent attack, which used a fake news release portal to impersonate the Indian Ministry of Defense, represents a minor but significant change in the architecture of malware read more about TAG 140 Deploys DRAT V2 RAT Targeting Indian Government Defense and Rail Sectors.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
