APT36 (Transparent Tribe), a Pakistan-linked threat group, has been observed targeting Indian government entities and diplomats with a high-volume wave of AI-generated, low-quality “vibeware” malware, according to Bitdefender research. The activity reflects a shift away from relying solely on established tooling toward rapidly producing disposable implants—often written in less common languages such as Nim, Zig, and Crystal—to increase throughput and potentially reduce detection by traditional antivirus signatures.
While much of the code is described as mediocre and error-prone (including examples of broken data-stealing logic), some capabilities are intrusive. Reported tooling includes LuminousCookies, which attempts to steal browser data by bypassing Chrome/Edge App-Bound Encryption by operating inside the browser’s memory context, and tradecraft intended to mislead attribution (e.g., embedding the common Hindu name “Kumar” in file paths and using culturally themed infrastructure naming such as a Discord server labeled “Jinwoo’s Server”). Bitdefender also assessed the vibeware approach as a “hybrid” fallback alongside known APT36-associated tooling and TTPs, including use of the open-source Havoc C2 framework and a shellcode loader referred to as Warcode, emphasizing scalability over sophistication and not relying on zero-days.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage framed APT36's activity as part of a wider trend of state-aligned actors using generative AI to accelerate malware and phishing development. Reports also cited Iran-aligned MuddyWater's alleged use of Google's Gemini and a Rust backdoor called 'Char,' with emoji-containing artifacts presented as possible evidence of AI-assisted development.
Bitdefender publicly documented APT36's AI-assisted malware production model, describing it as 'vibeware' and characterizing the tactic as a 'Distributed Denial of Detection' approach intended to overwhelm defenders with volume and diversity. The report highlighted unstable code, emoji-laden artifacts, and the use of polyglot malware in languages such as Nim, Zig, Crystal, Rust, Go, and C#.
Analysis of the campaign found APT36 gaining access through phishing, including ZIP/ISO archives with LNK files and resume-themed PDF lures that redirected victims to attacker-controlled downloads. Once inside, the group used in-memory PowerShell, custom loaders, and legitimate services such as Slack, Discord, Google Sheets, Supabase, and Firebase for command-and-control and data exfiltration.
Pakistan-linked APT36 (Transparent Tribe) began using generative AI to mass-produce large volumes of disposable malware aimed at Indian government entities, embassies, and other South Asia targets, with some reporting also noting Afghan government and private-sector victims. The campaign favored scale over sophistication, producing implants in multiple less common languages to reduce detection coverage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcehackread.com
Open sourcebankinfosecurity.com
Open sourcedarkreading.com
Open sourcebusinessinsights.bitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.