Pakistan-linked threat actor Transparent Tribe (APT36) has launched a targeted cyberespionage campaign against Indian government organizations, focusing on systems running the Bharat Operating System Solutions (BOSS) Linux distribution. The attackers used spear-phishing emails containing malicious ZIP archives or links to cloud-hosted files, which, when opened, executed a Bash command sequence to deploy the Golang-based DeskRAT malware. The campaign, observed since June 2025, leverages decoy PDFs related to Indian defense matters and employs multiple Linux-specific persistence mechanisms, including systemd services, cron jobs, autostart directory entries, and modifications to .bashrc.
DeskRAT establishes command-and-control via WebSockets, enabling remote file browsing, data exfiltration of files under 100 MB, and the ability to upload and execute additional payloads. Notably, the malware incorporates code potentially generated by large language models, accelerating its development and deployment. Researchers highlight that this use of AI tools by attackers is compressing malware development cycles, making detection and response more challenging for defenders. The campaign underscores the evolving sophistication of APT36 and the growing threat to Linux-based government infrastructure in India.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Multiple security outlets reported on a newly identified Transparent Tribe campaign targeting Indian government and BOSS Linux systems, attributing the activity to the Pakistan-linked group and detailing the use of DeskRAT malware. The public reporting consolidated findings on the phishing methods, malware capabilities, and targeting focus.
During August and September 2025, researchers observed Transparent Tribe deploying evolving DeskRAT variants, including AI-assisted and cross-platform tooling such as Linux- and Windows-capable components, with anti-analysis and payload delivery features. Reporting linked the activity specifically to attacks on India's BOSS Linux environment.
Transparent Tribe (APT36), a Pakistan-linked threat actor, conducted spear-phishing attacks against Indian government targets using malicious ZIP attachments and cloud-hosted links to deliver the Golang-based DeskRAT malware. The campaign targeted BOSS Linux systems and used WebSocket-based command-and-control, persistence mechanisms, and remote access capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.