APT36 is a highly sophisticated APT (Advanced Persistent Threat) group that is known for conducting targeted espionage in South Asia and is strongly linked to Pakistan.
While this APT group is known for targeting the following Indian sectors:-
Since 2013, this APT group has been active, and to conduct cyberespionage, it uses the following methods:-
Here below, we have mentioned the resources used by APT36:-
Zscaler analysts dubbed the Windows backdoor used by APT36 ‘ElizaRAT,’ because of unique strings in observed C2 commands.
ElizaRAT, delivered as .NET binaries in password-protected Google Drive archives, deploys as a Control Panel applet, launching CplApplet() and Main() functions that lead to malicious operations in MainAsync().
Protect your Business Email from threats like tracking, blocking, modifying, phishing, account takeover, business email compromise, malware, and ransomware with Trustifi’s AI-powered email security solution.
Each infected machine gets a unique identifier by combining the processorID and UUID with a ‘.cookie’ extension, serving as both UUID and username.
Here below, we have mentioned all the supported C2 commands:-
The bot generates a Windows shortcut (LNK) to ensure persistence in the Startup directory. It disguises itself as a ‘Text Editing APP for Windows,’ executing the Control Panel applet via rundll32.
The Program class’s dosome() method displays a distraction decoy PDF from the .NET binary’s resources, designed to mislead the user into thinking an error occurred.
APT36’s unique use of Linux desktop entry files in rare attacks is a first, with three undetected samples found since its inception in May 2023, used in a phishing scheme against the Indian government.
The cross-platform Linux payload, designed for Linux and WSL machines and lacking a complete C2 mechanism, suggests an initial test in its developmental phase by the threat actor.
The PDF mimics an Indian Defence Ministry document detailing a Saudi delegation’s discussion with Indian military medics.
APT36 uses Python-based ELF binaries for cyber espionage, targeting the Indian govt, Windows, and Linux systems. Here below, we have mentioned all the new Python-based cyber espionage utilities:-
Moreover, the ElizaRAT, distributed via harmful Google Drive links, allowed researchers to extract data about the Drive’s owner and linked email.
Keep informed about the latest cybersecurity news by following us on Google News, Linkedin, Twitter, and Facebook.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…