home.social

#transparenttribe — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #transparenttribe, aggregated by home.social.

fetched live
  1. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  2. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  3. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  4. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  5. PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

    A previously undocumented custom backdoor called PATCHCORD has been identified targeting Afghan telecom providers and South Asian critical infrastructure organizations. The C/C++ implant is delivered through sector-specific lures including fake VPN installers impersonating Afghan Telecom and telecom management tools. Infrastructure analysis uncovered SHEETCORD, a Go-based implant using Google Sheets for command-and-control, distributed via domains impersonating India's National Informatics Centre. The operation centers on a single C2 server with multiple associated domains impersonating Afghan telecom operators. An exposed staging server revealed SuperShell C2 framework, multiple RAT frameworks, credential harvesting tools, and exploit tooling for CVE-2024-6387. The activity shows moderate confidence overlap with APT36 (Transparent Tribe) based on targeting patterns, malware similarities, shared infrastructure, and operational tradecraft, representing an evolution of the group's capabilities with stronger ...

    Pulse ID: 6a7deb5e9423f6d0a5c5166d
    Pulse Link: otx.alienvault.com/pulse/6a7de
    Pulse Author: AlienVault
    Created: 2026-08-13 16:05:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CredentialHarvesting #CyberSecurity #Google #ICS #India #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SouthAsia #Telecom #TransparentTribe #VPN #bot #AlienVault

  6. 📢⚠️#Pakistan-linked APT36 is flooding Indian government networks with AI-generated “#Vibeware”, disposable malware built with AI. The campaign abuses trusted platforms like Google Sheets, Slack, and Discord for C&C

    Read: hackread.com/pakistan-apt36-in

  7. 📢⚠️#Pakistan-linked APT36 is flooding Indian government networks with AI-generated “#Vibeware”, disposable malware built with AI. The campaign abuses trusted platforms like Google Sheets, Slack, and Discord for C&C

    Read: hackread.com/pakistan-apt36-in

    #CyberSecurity #APT36 #TransparentTribe #Malware #AI #CyberAttack

  8. 📢⚠️#Pakistan-linked APT36 is flooding Indian government networks with AI-generated “#Vibeware”, disposable malware built with AI. The campaign abuses trusted platforms like Google Sheets, Slack, and Discord for C&C

    Read: hackread.com/pakistan-apt36-in

    #CyberSecurity #APT36 #TransparentTribe #Malware #AI #CyberAttack

  9. 📢⚠️#Pakistan-linked APT36 is flooding Indian government networks with AI-generated “#Vibeware”, disposable malware built with AI. The campaign abuses trusted platforms like Google Sheets, Slack, and Discord for C&C

    Read: hackread.com/pakistan-apt36-in

    #CyberSecurity #APT36 #TransparentTribe #Malware #AI #CyberAttack

  10. 📢⚠️#Pakistan-linked APT36 is flooding Indian government networks with AI-generated “#Vibeware”, disposable malware built with AI. The campaign abuses trusted platforms like Google Sheets, Slack, and Discord for C&C

    Read: hackread.com/pakistan-apt36-in

    #CyberSecurity #APT36 #TransparentTribe #Malware #AI #CyberAttack

  11. Discover how #TransparentTribe (#APT36) uses a disguised DESKTOP dropper to deploy #DeskRAT, a Golang RAT, on BOSS Linux endpoints in India.

    Our Sekoia #TDR report breaks down the full infection chain and stealthy WebSocket C2 communications .

    Read more 👉 blog.sekoia.io/transparenttrib

  12. Discover how #TransparentTribe (#APT36) uses a disguised DESKTOP dropper to deploy #DeskRAT, a Golang RAT, on BOSS Linux endpoints in India.

    Our Sekoia #TDR report breaks down the full infection chain and stealthy WebSocket C2 communications .

    Read more 👉 blog.sekoia.io/transparenttrib

  13. Discover how #TransparentTribe (#APT36) uses a disguised DESKTOP dropper to deploy #DeskRAT, a Golang RAT, on BOSS Linux endpoints in India.

    Our Sekoia #TDR report breaks down the full infection chain and stealthy WebSocket C2 communications .

    Read more 👉 blog.sekoia.io/transparenttrib

  14. Discover how #TransparentTribe (#APT36) uses a disguised DESKTOP dropper to deploy #DeskRAT, a Golang RAT, on BOSS Linux endpoints in India.

    Our Sekoia #TDR report breaks down the full infection chain and stealthy WebSocket C2 communications .

    Read more 👉 blog.sekoia.io/transparenttrib

  15. 📌 Transparent Tribe (APT36) has leveled up.
    Their phishing campaigns now use malicious Linux & Windows desktop shortcuts to break into Indian government systems.
    ➡️ Fake PDF → Malware → Persistence → Data theft.
    👀 Do you think orgs are ready for attacks that adapt across platforms?
    💬 Share in the comments & follow @technadu for more cyber insights.

    #TransparentTribe #APT36 #Linux #BOSS #CyberEspionage #Phishing #IndianGovt

  16. 📌 Transparent Tribe (APT36) has leveled up.
    Their phishing campaigns now use malicious Linux & Windows desktop shortcuts to break into Indian government systems.
    ➡️ Fake PDF → Malware → Persistence → Data theft.
    👀 Do you think orgs are ready for attacks that adapt across platforms?
    💬 Share in the comments & follow @technadu for more cyber insights.

    #TransparentTribe #APT36 #Linux #BOSS #CyberEspionage #Phishing #IndianGovt

  17. Pakistan’s Transparent Tribe targets Indian defence sector with new malware using fake PowerPoint files to breach BOSS Linux systems.

    Read: hackread.com/pakistan-transpar

  18. [Threatview.io]⚡️Some domains likely used by #transparentTribe targetting #India

    counciling[.]com
    nbssedelhi[.]org
    ashifdigitalseva[.]xyz
    birthdeath[.]in
    gov-certificate[.]com
    viewss[.]click
    admin-mcas-df[.]ms
    admin-mcas[.]ms
    mcas-df[.]ms
    mcas[.]ms
    verifycertificate[.]info
    nimsme[.]org

    #threatintel
    #dfir
    #apt

  19. [Threatview.io]⚡️Some domains likely used by #transparentTribe targetting #India

    counciling[.]com
    nbssedelhi[.]org
    ashifdigitalseva[.]xyz
    birthdeath[.]in
    gov-certificate[.]com
    viewss[.]click
    admin-mcas-df[.]ms
    admin-mcas[.]ms
    mcas-df[.]ms
    mcas[.]ms
    verifycertificate[.]info
    nimsme[.]org

    #threatintel
    #dfir
    #apt

  20. [Threatview.io]⚡️Some domains likely used by #transparentTribe targetting #India

    counciling[.]com
    nbssedelhi[.]org
    ashifdigitalseva[.]xyz
    birthdeath[.]in
    gov-certificate[.]com
    viewss[.]click
    admin-mcas-df[.]ms
    admin-mcas[.]ms
    mcas-df[.]ms
    mcas[.]ms
    verifycertificate[.]info
    nimsme[.]org

    #threatintel
    #dfir
    #apt