Cosmic Leopard is described as a Pakistan-linked cyber-espionage threat actor overlapping with APT36 (Transparent Tribe). Reporting attributes to this ecosystem sustained intelligence-collection activity targeting Indian government agencies and defense-, technology-, academic-, research-, and other strategic institutions through 2024 into 2025, with objectives assessed as long-term espionage rather than destructive or financially motivated operations. Tradecraft described includes spear-phishing as initial access, commonly delivering ZIP archives containing weaponized Windows shortcut (.LNK) files masquerading as documents (e.g., double-extension “.pdf.lnk”), leading to execution chains that launch mshta.exe and/or PowerShell to retrieve additional stages. Follow-on payload delivery is reported via ISO images. Tooling referenced in the reporting includes Golang-based components (GOGITTER downloader; GITSHELLPAD backdoor using GitHub for C2; GOSHELL as a loader for Cobalt Strike Beacon), custom RAT DLLs (e.g., ki2mtmkl.dll, iinneldc.dll), and malware components named ReadOnly and WriteOnly enabling remote control, data exfiltration, persistent surveillance, screenshots, remote desktop access, and clipboard monitoring. Persistence mechanisms described include scheduled tasks, registry modifications, and startup folder shortcuts, with behavior adapting based on installed antivirus products (including Kaspersky, Quick Heal, Avast, AVG, and Avira). Command-and-control and exfiltration are described as using encrypted HTTP/S, dynamic DNS, and cloud services (including Google Sheets, Firebase, and GitHub). The operators are reported to use localized lures (government exams, defense projects, urgent official notices) and fake update dialogs (e.g., Adobe Acrobat Reader DC), and to gate payload delivery to Indian IP ranges and Windows user agents. Android targeting is also described via CapraRAT spyware delivered through malicious apps masquerading as legitimate government or utility applications, with capabilities including access to SMS, call logs, location, microphone, and camera. Reported infrastructure includes domains such as adobe-acrobat[.]in, innlive[.]in, and drjagrutichavan[.]com. Public reporting referenced includes CYFIRMA, The Hacker News, and Recorded Future, and example campaign names mentioned include “Gopher Strike” and “Sheet Attack.”
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a Pakistan-linked group with operational overlap with APT36; no additional campaign details provided in the content.
Cosmic Leopard has conducted espionage campaigns against Indian government agencies and defense- and technology-related companies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.