Skip to main content
Mallory
MalwareUsed by 2 actors

CrimsonRAT

CrimsonRAT is a Windows .NET-based remote access trojan used by Transparent Tribe/APT36, a suspected Pakistan-linked threat actor, and has been described as the group’s primary malware since at least 2020 and its malware of choice for establishing long-term access in victim networks. Reported delivery has relied on spear-phishing and phishing attacks, including malicious Office documents with VBA macros that extract an embedded archive, unzip it, and execute the payload. Campaigns cited in the content targeted Indian entities, including defense, government, critical infrastructure, and educational institutions/students, and the group has historically targeted government employees, military personnel, think tanks, conferences, and also used CrimsonRAT against human rights activists in Pakistan. Documented capabilities include directory and drive listing, process listing, screenshot capture, file read/write/delete, arbitrary command execution, exfiltration to command-and-control servers, and the ability to run or manage keylogger and USB-related modules while reporting their presence or versions to C2. The content also notes overlap in maldocs and macros with ObliqueRAT campaigns, and places CrimsonRAT in Transparent Tribe’s tooling evolution as the Windows family used in parallel with later Linux-focused families such as Poseidon, AresRAT, and DeskRAT. High-confidence infrastructure and campaign details directly tied to CrimsonRAT in the content include student-themed domains such as studentsportal[.]live, studentsportal[.]website, and studentsportal[.]co; additional cloud/media-themed domains cloud-drive[.]store, user-onedrive[.]live, and drive-phone[.]online; subdomains under geo-news[.]tv including cloud-drive.geo-news.tv, drive-phone.geo-news.tv, studentsportal.geo-news.tv, and user-onedrive.geo-news.tv; shared IP 198[.]37[.]123[.]126; and related hosting/name-service links involving vebhost[.]com and zainhosting[.]net.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Transparent Tribe

Quick Heal’s team has identified hacker group APT36 (Transparent Tribe) deploying CrimsonRAT malware through sophisticated phishing attacks along with an RMM tool known as MeshAgent, he said.

via economictimes indiatimeseconomictimes.indiatimes.com
TransparentTribe

“improving its custom .NET tool named CrimsonRAT.”

via securelistsecurelist.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence2

Quick Heal’s team has identified hacker group APT36 (Transparent Tribe) deploying CrimsonRAT malware through sophisticated phishing attacks along with an RMM tool known as MeshAgent, he said.

T1566.001Spearphishing AttachmentEvidence1

The current lure is themed as Ministry of Defence procurement of indigenous trawl assemblies for T-72 and T-90 main battle tanks ... a plausible-enough artifact for a defense-contracting inbox to open without hesitation.

Stealth

1 technique
T1036MasqueradingEvidence1
TacticStealth

The current lure is themed as Ministry of Defence procurement of indigenous trawl assemblies for T-72 and T-90 main battle tanks — a plausible-enough artifact for a defense-contracting inbox to open without hesitation.

T1219Remote Access ToolsEvidence1

Quick Heal’s team has identified hacker group APT36 (Transparent Tribe) deploying CrimsonRAT malware through sophisticated phishing attacks along with an RMM tool known as MeshAgent, he said.

INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app14 days ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.