The threat actor known as Transparent Tribe, or APT36, has launched a new wave of cyber espionage campaigns targeting Indian government, academic, and strategic organizations. These attacks leverage spear-phishing emails containing ZIP archives with Windows LNK shortcut files disguised as legitimate PDF documents. When opened, these shortcuts execute remote HTML Application (HTA) scripts using mshta.exe, which in turn decrypt and load a .NET-based Remote Access Trojan (RAT) directly into memory, providing the attackers with persistent remote control, data theft, and surveillance capabilities. The campaigns employ sophisticated evasion techniques, such as embedding full PDF content and images within the LNK files to avoid suspicion, and adapting persistence methods based on detected antivirus solutions.
Researchers from Cyfirma have detailed how the malware communicates with its command-and-control infrastructure over encrypted channels and uses trusted Windows tools to evade detection. The infection chain is designed for long-term spying, with the attackers able to profile the victim's environment and manipulate runtime execution for reliability. The use of double extension tricks and abnormal file sizes further enhances the campaign's effectiveness in deceiving targets. These campaigns highlight the evolving tactics of APT36 and the ongoing threat posed to Indian governmental and strategic sectors by state-sponsored cyber espionage groups.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Cyfirma researchers documented the campaign's use of mshta.exe, remote HTA scripts, in-memory .NET RAT loading, decoy documents, and abuse of trusted Windows components for evasion. Reporting also identified malware components and RAT capabilities including remote control, surveillance, data theft, persistence, and clipboard monitoring.
Transparent Tribe (APT36) initiated a spear-phishing campaign targeting Indian government, academic, and other strategic entities using ZIP archives themed around the "Online JLPT Exam Dec 2025." The lures delivered malicious Windows LNK files disguised as PDFs to begin a multi-stage intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.