ESET reported that Transparent Tribe (also tracked as APT36) ran an Android espionage campaign that used trojanized messaging apps, MeetsApp and MeetUp, to infect people in India and Pakistan who likely had military or political relevance. The operation appears to have relied on honey-trap romance lures, directing targets to fake download sites instead of Google Play, while the apps retained normal chat features to avoid suspicion and covertly installed the CapraRAT backdoor.
Once installed, the malware enabled broad surveillance, including screenshots, photo capture, audio and call recording, SMS access, contact theft, file exfiltration, and location tracking. ESET linked the activity to Transparent Tribe through reused CapraRAT code, shared command-and-control infrastructure, the same signing certificate, and overlap with domains previously tied to the group; researchers also said poor operator security exposed victim data, allowing them to identify more than 150 victims across India, Pakistan, Russia, Oman, and Egypt.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
On March 7, 2023, ESET published findings on an active Transparent Tribe espionage campaign involving trojanized Android messaging apps that retained chat features while adding spyware capabilities such as screenshot capture, audio recording, SMS access, contact theft, file exfiltration, and location tracking. ESET linked the activity to Transparent Tribe through shared infrastructure, reused CapraRAT code, the same C2 server and signing certificate, and said poor operator security exposed victim PII from more than 150 victims across several countries.
ESET reported that a Transparent Tribe (APT36) campaign using trojanized Android apps named MeetsApp and MeetUp to deliver the CapraRAT backdoor appears to have been active since at least July 2022. The operation likely used romance-scam-style lures and fake distribution websites to target people in India and Pakistan with likely military or political relevance.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.