APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign
A threat actor with ties to Pakistan has been seen launching spear-phishing operations against Indian government organizations in an attempt to spread DeskRAT, a Golang-based malware.
Sekoia saw the activity in August and September of 2025, and it has been linked to Transparent Tribe (also known as APT36), a state-sponsored hacker collective that has been active since at least 2013. Additionally, it expands on a previous campaign that CYFIRMA revealed in August 2025.
Phishing emails with a ZIP file attachment or, occasionally, a link to an archive stored on reputable cloud services like Google Drive are part of the attack chains. The ZIP package contains malicious desktop file embedding commands that, when run alongside the main payload, cause Mozilla Firefox to display a phony PDF ...

