Investigating APT36 or Earth Karkaddan’s Attack Chain and Malware Arsenal
What it means
MISP EudorIA ha pubblicato l'advisory "Investigating APT36 or Earth Karkaddan’s Attack Chain and Malware Arsenal". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: Investigating APT36 or Earth Karkaddan’s Attack Chain and Malware Arsenal. Report from - [URL rimossa] (1644251515) # Investigating APT36 or Earth Karkaddan’s Attack Chain and @[tag](misp-galaxy:financial-fraud="Malware") Arsenal We investigated the most recent activities of APT36, also known as Earth Karkaddan, a politically motivated advanced persistent threat (APT) group, and discuss its use of CapraRAT, an Android RAT with clear similarities in design to the group’s favored Windows malware, @[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="Crimson")")") RAT. By: Trend Micro January 24, 2022 Read time: ( words) APT36, also known as Earth Karkaddan, a politically motivated advanced persistent threat (APT) group, has historically targeted Indian military and diplomatic resources. This APT group (also referred to as Operation C-Major, PROJECTM, Mythic Leopard, and Transparent Tribe) has been known to use social engineering and phishing lures as an entry point, after which, it deploys the @[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="Crimson")")") RAT malware to steal information from its victims. In late 2021, we saw the group leverage CapraRAT, an Android RAT with clear similarities in design to the group’s favored Windows malware, @[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="Crimson")")"
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it · translation not needed
- Publication
- 30/07/2026 02:46
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 92
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 82Last sharing verification: 2026-09-26T09:31:29.840625+00:00
- MISP event
- 34582dfc-d0bf-403d-8419-2d4fa7a76466
- Classification
- Low