Transparent Tribe, commonly tracked as APT36, is a Pakistan-aligned cyber espionage threat actor focused primarily on South Asian targets, especially Indian government, military, diplomatic, defense, and education entities. Reported aliases include APT36, Mythic Leopard, ProjectM, Earth Karkaddan, Operation C-Major, Copper Fieldstone, Storm-0156, and Transparent Tribe. SideCopy is frequently described as a related cluster or sub-group operating under the broader Transparent Tribe umbrella, though reporting on the exact relationship varies. The group has been active since at least the mid-2010s and is widely associated with sustained intelligence collection against Indian strategic interests. Targeting has expanded over time beyond traditional government and military victims to include students, job seekers, activists, diplomatic organizations, and, in some reporting, Afghan government finance personnel. Transparent Tribe has also conducted Android-focused surveillance operations against individuals of likely military or political relevance in India and Pakistan. Transparent Tribe is known for heavy use of spearphishing and social engineering. Common lures include defense, diplomatic, recruitment, education, and current-affairs themes tailored to regional targets. Delivery mechanisms have included malicious Office documents, archives, shortcut files, ISO images, OLE-embedded content, and trojanized Android applications distributed through actor-controlled websites. The actor has repeatedly abused legitimate services and platforms for staging, command and control, or victim management, including cloud storage, remote management software, and Google services such as Google Sheets and Google Drive. Malware associated with Transparent Tribe includes CrimsonRAT, CapraRAT, and other custom .NET and Android implants, as well as campaigns using Google Sheets-backed command and control and remote management tooling. CrimsonRAT has been a long-running Windows espionage implant family used for capabilities such as system reconnaissance, file theft, screenshot capture, process control, and broader remote access. Newer variants have shown increased obfuscation, anti-analysis checks, persistence logic, and support functions consistent with espionage operations. CapraRAT is the group’s Android surveillance platform, typically embedded in trojanized chat, dating, video, or entertainment apps while preserving enough benign functionality to reduce suspicion. Reported mobile capabilities include collection of SMS messages, contacts, call logs, files, screenshots, photos, audio, location, and other device data, along with command execution and device-control features. Tradecraft commonly attributed to Transparent Tribe includes spearphishing attachments, user execution, PowerShell-based loaders, scheduled-task or startup persistence, hidden files and directories, masquerading with Windows-like names, anti-VM and anti-sandbox checks, and use of legitimate binaries or services to blend into normal activity. Campaigns have also shown use of decoy documents, staged payload hosting on actor-controlled or compromised infrastructure, and cloud-mediated command channels designed to evade network-based detection. Operationally, Transparent Tribe demonstrates persistent regional focus, iterative malware development, and pragmatic use of commodity and custom tooling. Its campaigns are generally aligned with espionage objectives rather than disruptive effects, with collection priorities centered on defense, government, diplomatic, and politically sensitive information relevant to Pakistan’s strategic interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
51 malware families attributed to this actor across reporting.
46 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
the attachment was a weaponized RTF document utilizing CVE-2012-0158 to drop an embedded, encoded portable executable (PE)... In multiple lure documents, Type: Exploit, CVE-2012-0158, Embedded Payload.
...has exploited CVE-2012-0158 and CVE-2010-3333 for execution against targeted systems.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
"...we saw attackers making use of template injection attack and equation editor vulnerability (CVE-2017-11882) as the initial infection vector."
515 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Assessed as likely behind Operation ShadowRecruit, a multi-stage malware campaign targeting Indian government job seekers using recruitment-themed lures, ControlR for remote access, and a custom .NET RAT (SheetAgent) using Google Sheets as backup C2.
Likely associated with a multi-stage malware campaign targeting Indian government job seekers, using recruitment-themed lures, ControlR for remote access, and a custom .NET RAT ('SheetAgent') using Google Sheets as a backup C2 channel.
Linked with moderate confidence to an espionage campaign using the SHEETCREEP remote access trojan, delivered via phishing emails themed around the “UAE-India Strategic Partnership Week,” and abusing Google Sheets as command-and-control infrastructure.
Pakistan-linked threat actor referenced as the broader group associated with SideCopy and known for targeting neighboring countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.