Researchers reported that Pakistani-linked espionage operations continued to target Indian defense, government, police, and technology-related personnel with evolving malware delivered through spear phishing, social engineering, and trojanized applications. Cisco Talos said Operation Celestial Force, attributed to the Cosmic Leopard cluster, has run since at least 2018 and uses a cross-platform toolset including GravityRAT for Windows and Android, the HeavyLift Electron-based loader, and the GravityAdmin campaign management utility. Earlier Securelist research showed GravityRAT had already expanded from Windows into Android and macOS, using fake apps and spoofed update domains to steal device data, messages, call logs, documents, screenshots, keystrokes, and other files while maintaining persistence and enabling remote command execution.
Separate reporting tied APT36 / Transparent Tribe / Mythic Leopard to parallel campaigns against Indian military and government targets using counterfeit apps and themed lures. Securelist documented trojanized Android apps, including a fake Aarogya Setu app, that deployed a modified AhMyth RAT capable of downloading additional APKs, recording audio, deleting selected SMS messages, and exfiltrating contacts, WhatsApp media, documents, and other data. BleepingComputer, citing Talos, also described fake Kavach authentication apps used to infect Indian government employees with updated CrimsonRAT and a lightweight .NET RAT, underscoring a sustained effort to refine mobile and desktop surveillance malware for intelligence collection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
27 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos disclosed Operation Celestial Force in June 2024 and attributed it with high confidence to a Pakistani threat cluster it tracks as Cosmic Leopard. Talos described a long-running espionage campaign using GravityRAT, HeavyLift, and GravityAdmin against Indian targets.
Brandefense reported a Transparent Tribe/APT36 espionage campaign targeting Indian government-related users on UNIX-based systems with a fake Kavach-themed lure. The operation used a first-stage ELF/Python downloader to establish persistence and fetch a second-stage Poseidon agent from the open-source Mythic C2 framework.
ESET published research in June 2023 on Android GravityRAT going after WhatsApp backups, indicating a new technical detail in the malware's data theft behavior.
Talos said APT36 continued using CrimsonRAT in the Kavach-themed campaign and had expanded it with keylogging, arbitrary command execution, file reading, and file deletion. The actor also deployed a lightweight .NET RAT, possibly for redundancy or as a developing custom implant.
Cisco Talos reported a campaign targeting Indian government entities using trojanized Kavach authentication apps distributed through counterfeit websites impersonating legitimate Indian government sites. Victims received a legitimate-looking installer alongside a malicious payload that initiated infection.
Talos analyzed multiple GravityAdmin administration panel binaries and found the earliest were compiled in August 2021. GravityAdmin was used to manage GravityRAT and HeavyLift infections across named campaigns.
BleepingComputer, citing Talos, said APT36 used ObliqueRAT in 2021 in narrowly targeted attacks against government personnel. The infection vector involved emails with VBS-laced documents.
Seqrite reported that in 2020 APT36 conducted Operation Honey Trap, targeting personnel in Indian defence and other government organizations using fake female personas, spear-phishing emails, and messaging-based social engineering. The campaign delivered MSIL-based Crimson RAT through macro-enabled documents and ZIP-contained droppers, and the report published associated IOCs.
Kaspersky reported that sharingmymedia[.]com was registered on 2020-01-10 via NameSilo using the same registrant information as sharemydrives[.]com. The domain later hosted lure documents in Transparent Tribe operations.
Kaspersky reported that the domain sharemydrives[.]com was registered via NameSilo on 2020-01-03 using registrant details later shared with related infrastructure. The domain was used in Transparent Tribe activity.
BleepingComputer reported that CrimsonRAT was first observed in APT36 campaigns in 2020. The malware supported credential theft, process listing, payload retrieval, and screenshot capture.
Kaspersky found that sharemydrives[.]com hosted wifeexchange.exe, a porn-themed dropper that extracted frame.exe and movie.mp4. The frame.exe sample matched ObliqueRAT-related malware previously described by Cisco Talos.
Kaspersky identified a new Transparent Tribe Android malware chain distributed in India as both a porn-themed app and a fake Aarogya Setu COVID-19 tracking app. The trojanized apps deployed a modified AhMyth RAT for surveillance and data theft.
Securelist noted that the certificate used to sign the Titanium application was revoked on 2019-09-08. The certificate had previously been used in GravityRAT-related malware distribution.
Securelist reported that a PyInstaller-packed enigma.exe in the Enigma malware chain was signed by E-Crea Limited on 2019-05-09. The sample was distributed from enigma.net[.]in while posing as a secure file-sharing application.
A GravityRAT-related application named Titanium was signed by Plano Logic Ltd on 2019-04-14 before later certificate revocation. It was hosted at titaniumx.co[.]in.
Securelist said researchers found an Android spyware sample on VirusTotal in 2019 that appeared connected to GravityRAT. The sample was a trojanized Travel Mate app renamed Travel Mate Pro.
Talos reported that Cosmic Leopard added HeavyLift, an Electron-based malware loader, in 2019. It was distributed through malicious installers as part of the campaign's expanding toolkit.
Securelist found the attackers used a GitHub-published Travel Mate source version from October 2018 and inserted malicious code into it, creating the Android spyware app Travel Mate Pro.
Researchers reported that GravityRAT expanded beyond Windows to target Android devices in 2018. Talos similarly assessed the broader operation moved to Android around 2019.
Cisco Talos said Operation Celestial Force has been active since at least 2018. The espionage campaign targeted Indian individuals and entities, especially in defense, government, and related technology sectors.
Cisco Talos published research on GravityRAT in 2018, describing spyware used to target the Indian armed forces. Talos later referenced this as its first disclosure of the Windows-based malware.
Securelist says India's CERT-IN first discovered the GravityRAT Trojan in 2017. This marks an early documented identification of the malware family.
Unit 42 reported that a targeted campaign it tracks as ProjectM overlapped with Operation Transparent Tribe and Operation C-Major, targeting Indian government and military personnel. The report tied campaign infrastructure and malware-related domains to exposed WHOIS records and online accounts associated with a Pakistan-based individual, while stopping short of definitive attribution.
Securelist reported that the GravityRAT espionage campaign has been active since at least 2015, targeting Indian defense, police, and related organizations. The operators are believed to be Pakistani threat actors.
Kaspersky's analysis states that Transparent Tribe, also known as PROJECTM or MYTHIC LEOPARD, has been active since at least 2013 and typically targets Indian military and government personnel.
At the end of April, the Indian Army warned personnel about malicious apps resembling Aarogya Setu that were allegedly used by Pakistani agencies to target Indian military phones. Public reporting said the apps were sent to WhatsApp groups of Indian Army personnel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcebrandefense.io
Open sourcewelivesecurity.com
Open sourcebleepingcomputer.com
Open sourcesecurelist.com
Open sourcesecurelist.com
Open sourceseqrite.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.