ReadOnly is a malware component used in a cyber-espionage campaign attributed to APT36 (Transparent Tribe), a Pakistan-aligned threat actor. In the reported campaign, spear-phishing emails delivered a ZIP archive containing a malicious file disguised as a PDF; when opened, it deployed two malware components, ReadOnly and WriteOnly. ReadOnly is described as enabling remote control of infected systems, data exfiltration, and persistent surveillance. Reported capabilities include capturing screenshots, monitoring clipboard activity, enabling remote desktop access, and maintaining access on victim machines. The malware is also described as quietly embedding itself on compromised hosts and adjusting its behavior based on the antivirus software installed. The campaign targeted Indian government, academic, and strategic institutions and was assessed as aligned with intelligence-gathering objectives rather than financial gain. Cyfirma reported that the activity reflected APT36’s evolving tradecraft, including abuse of trusted Windows components and fileless execution techniques. A noted risk from the clipboard-monitoring functionality is theft or overwriting of copied data, including potential hijacking of cryptocurrency transactions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access/backdoor malware used for espionage: remote control, data theft, clipboard monitoring, screenshot capture, and persistence.
ReadOnly is a malware component used by APT36 for cyber-espionage. It provides remote access, data exfiltration, persistent surveillance, screenshot capture, clipboard monitoring, and remote desktop access. It adapts its behavior based on installed antivirus software.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.