A new wave of attacks against Indian governmental, academic, and strategic organizations using a remote access trojan (RAT) that gives them long-term control over infected hosts has been linked to the threat actor Transparent Tribe.
In order to avoid user suspicion, the campaign uses deceptive distribution mechanisms, such as a weaponized Windows shortcut (LNK) file that is embedded with complete PDF content and poses as a valid PDF document, according to a technical assessment from CYFIRMA.
The hacking group Transparent Tribe, commonly known as APT36, is well-known for launching cyberespionage operations against Indian businesses. The state-sponsored enemy, thought to be of Indian descent, has been operating since at least 2013.
To achieve its objectives, the threat actor has an ever-evolving arsenal of RATs. CapraRAT, Crimson RAT, ElizaRAT, and DeskRAT are a few of the trojans that Transparent Tribe has used recently read more about Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
