Pakistan-linked threat activity targeting Indian organizations has expanded across government, defense, education, and energy sectors, with researchers tying much of the activity to Transparent Tribe (APT36) and SideCopy. Seqrite reported that SideCopy ran multiple spear-phishing campaigns using malicious LNK files, MSHTA, staged HTA and DLL payloads, and dual AllaKore RAT variants against Indian government and military-themed targets, while Transparent Tribe used XLAM add-ins, macro-enabled files, and updated Crimson RAT delivery chains. Infrastructure overlaps, malware similarities, and passive DNS correlations were cited as evidence linking the groups, and lures referenced Indian Ministry of Defence allowances, DGMS themes, and Army posting policies to increase credibility.
Other reporting shows the same broader espionage pattern has persisted for years and widened beyond traditional military targets. SentinelOne, K7, and Seqrite documented Transparent Tribe campaigns against Indian educational institutions using malicious Office documents and .NET malware with Crimson RAT-like behavior, while Cyble described a defense-themed malware chain delivered in a .vhdx image that checked for India Standard Time before deploying a second-stage payload. Separately, EclecticIQ's Operation FlightNight targeted Indian government entities and private energy companies with an ISO-delivered stealer based on HackBrowserData, exfiltrating browser data and selected documents to attacker-controlled Slack workspaces; analysts linked it to an earlier Go-Stealer campaign and assessed the motive as cyber espionage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
K7 Labs analyzed a campaign attributed to Transparent Tribe that used an Indian election-results document and a Delhi university syllabus-themed Excel file to deliver Crimson RAT. The malware established persistence, used long sleep delays to evade analysis, and attempted to contact waqers.duckdns.com and 94.72.105.227 for command-and-control.
Seqrite reported increased attacks on Indian government and defense entities by Pakistan-linked groups SideCopy and Transparent Tribe. The report said infrastructure overlaps, malware similarities, and passive DNS correlations supported high-confidence attribution and reinforced the assessment that Transparent Tribe is the parent group of SideCopy.
Seqrite reported that a recent Transparent Tribe Crimson RAT sample carried a compile timestamp of 2024-03-17. The sample reflected updated delivery methods using XLAM maldocs and retained the malware's core command-and-control functionality.
EclecticIQ identified Operation FlightNight as active from at least March 7, 2024, targeting Indian government entities and private energy companies. The campaign used an Indian Air Force-themed phishing lure to deliver a modified HackBrowserData stealer that exfiltrated data to attacker-controlled Slack workspaces.
Seqrite observed three SideCopy campaigns over March and April 2024 that used spear-phishing archives with double-extension LNK files, MSHTA, staged HTA and DLL payloads, and ultimately deployed two AllaKore RAT variants simultaneously. The lures were themed around Indian Ministry of Defence subjects and used compromised domains and Contabo-hosted infrastructure.
EclecticIQ said the earlier Go-Stealer campaign was reported by researcher ElementalX2 and later found to share five overlaps with Operation FlightNight. Those similarities led EclecticIQ to assess that both campaigns were likely conducted by the same threat actor.
Seqrite detailed an active Transparent Tribe campaign using malicious PPAM files themed around the 'Revision of Officers posting policy' to target the Indian Army. The infection chain delivered a .NET-based Crimson RAT payload with persistence and support for 22 commands.
Seqrite said Transparent Tribe's increased targeting of Indian educational institutions peaked in February 2023. The activity was described as a continuation of earlier IIT-focused operations that expanded to NITs and business schools.
K7 Labs analyzed a Transparent Tribe phishing campaign using a macro-enabled document masquerading as an Indian Institute of Technology Hyderabad survey form. The payload dropped an obfuscated .NET executable, established Run-key persistence, collected host and image metadata, and attempted to contact sunnyleone[.]hopto[.]org over multiple custom TCP ports.
Seqrite reported that Transparent Tribe had been targeting the education sector since May 2022, marking an expansion beyond its traditional government and military focus. The activity later broadened from IITs to NITs and business schools.
Cyble Research Labs published analysis of a two-stage .NET malware delivered in a VHDX file impersonating the Indian Armed Forces' Canteen Store Department. The malware checked for India Standard Time, downloaded a second-stage payload, established persistence, and communicated with a C2 at 45.147.228.195:5434.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
labs.k7computing.com
Open sourceseqrite.com
Open sourceblog.eclecticiq.com
Open sourceseqrite.com
Open sourcesentinelone.com
Open sourcelabs.k7computing.com
Open sourceblog.cyble.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.