Transparent Tribe (APT36), a Pakistan-aligned threat actor historically associated with espionage against Indian government, defense, and education targets, has been observed expanding operations into India’s startup ecosystem, with a particular focus on startups connected to cybersecurity, intelligence, and law-enforcement support. Researchers reported the activity after identifying suspicious, India-origin uploads and startup-themed lure material, including the apparent use of personal details tied to a real startup founder to increase the credibility of spear-phishing content.
The intrusion chain described relies on spear-phishing emails delivering an ISO container (e.g., MeetBisht.iso) that includes a malicious LNK shortcut masquerading as a legitimate document (such as an Excel file) plus a hidden folder containing a decoy document, a batch script to execute/maintain the infection flow, and the Crimson RAT payload (disguised as an executable named like Excel). Once installed, Crimson RAT enables broad surveillance and control capabilities (e.g., screen monitoring, audio recording, file theft, and system control), aligning with APT36’s established intelligence-collection objectives even as targeting broadens to startup-linked individuals with proximity to sensitive government or security operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Acronis researchers disclosed technical details of the Transparent Tribe campaign, including its use of ISO container attachments, trusted user-directory execution, decoy documents, custom TCP command-and-control communications, and evasion techniques such as junk-data padding and randomized function names. The reporting highlighted Crimson RAT's surveillance and theft capabilities against targeted Indian startups.
Pakistan-linked Transparent Tribe (APT36) shifted its targeting from Indian government and defense organizations to India's technology startup sector, with particular interest in cybersecurity and intelligence-related firms. The campaign used spearphishing emails with ISO attachments to deliver Crimson RAT through a multi-stage infection chain involving malicious LNK, batch, and PowerShell components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.