WriteOnly is a malware component used in a cyber-espionage campaign attributed to APT36 (Transparent Tribe), a Pakistan-aligned threat actor. In the reported campaign, spear-phishing emails delivered a ZIP archive containing a malicious file disguised as a PDF; when opened, it deployed two malware components, ReadOnly and WriteOnly. WriteOnly is described as enabling remote control of infected systems, data exfiltration, and persistent surveillance. Reported capabilities include capturing screenshots, monitoring clipboard activity, and enabling remote desktop access, while maintaining access on victim machines. The malware is also said to quietly embed itself on compromised hosts and adjust its behavior based on the antivirus software installed. The campaign targeted Indian government, academic, and strategic institutions and was assessed as aligned with long-term intelligence-gathering objectives rather than financial motives. Cyfirma reported that the broader operation reflected APT36’s evolving tradecraft, including abuse of trusted Windows components and fileless execution techniques. A noted operational risk from the clipboard-monitoring functionality is theft or overwriting of copied data, including possible hijacking of cryptocurrency transactions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access/backdoor malware used for espionage: remote control, data theft, clipboard monitoring, screenshot capture, and persistence.
WriteOnly is a malware component deployed by APT36 for espionage. It enables remote control, data exfiltration, persistent surveillance, screenshot capture, clipboard monitoring, and remote desktop access, with adaptive behavior based on antivirus presence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.