Transparent Tribe (APT36), a suspected Pakistan-aligned threat actor, targeted India’s education sector with malicious Microsoft Office documents designed to deliver Crimson RAT. Researchers said the campaign used both traditional macro-enabled files and a newer OLE embedding technique that tricks victims into double-clicking a fake "View Document" prompt, launching the malware under the filename MicrosoftUpdate.exe.
SentinelOne identified multiple Crimson RAT .NET variants compiled between July and September 2022 that used the command-and-control domain richa-sharma.ddns[.]net. The samples showed anti-analysis delays, persistence checks, and differing obfuscation approaches, including Eazfuscator, indicating continued tool refinement as the group broadened its targeting beyond Indian military and government entities to include educational institutions and students across the subcontinent.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SentinelLABS observed multiple Crimson RAT .NET variants associated with Transparent Tribe that were compiled between July and September 2022. The malware used the C2 domain richa-sharma.ddns[.]net and included anti-analysis delays, persistence checks, and varying obfuscation methods including Eazfuscator.
SentinelLABS reported that Transparent Tribe (APT36), a suspected Pakistan-aligned threat actor, continued targeting the Indian education sector with malicious Office documents delivering Crimson RAT. The campaign showed tactical evolution through both traditional Office macros and newly observed OLE embedding that tricks victims into launching Crimson RAT disguised as MicrosoftUpdate.exe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.