EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Investigating APT36 or Earth Karkaddan’s Attack Chain and Malware Arsenal

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 55/100

MISP EudorIA ha pubblicato l'advisory "Investigating APT36 or Earth Karkaddan’s Attack Chain and Malware Arsenal". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: Investigating APT36 or Earth Karkaddan’s Attack Chain and Malware Arsenal. Report from - [URL rimossa] (1644251515) # Investigating APT36 or Earth Karkaddan’s Attack Chain and @[tag](misp-galaxy:financial-fraud="Malware") Arsenal We investigated the most recent activities of APT36, also known as Earth Karkaddan, a politically motivated advanced persistent threat (APT) group, and discuss its use of CapraRAT, an Android RAT with clear similarities in design to the group’s favored Windows malware, @[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="Crimson")")") RAT. By: Trend Micro January 24, 2022 Read time: ( words) APT36, also known as Earth Karkaddan, a politically motivated advanced persistent threat (APT) group, has historically targeted Indian military and diplomatic resources. This APT group (also referred to as Operation C-Major, PROJECTM, Mythic Leopard, and Transparent Tribe) has been known to use social engineering and phishing lures as an entry point, after which, it deploys the @[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="Crimson")")") RAT malware to steal information from its victims. In late 2021, we saw the group leverage CapraRAT, an Android RAT with clear similarities in design to the group’s favored Windows malware, @[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="@[tag](misp-galaxy:mitre-malware="Crimson")")"

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it · translation not needed
Publication
30/07/2026 02:46
Sharing
TLP:CLEAR
Indicators reported by the source
92
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
82Last sharing verification: 2026-09-26T09:31:29.840625+00:00
MISP event
34582dfc-d0bf-403d-8419-2d4fa7a76466
Classification
Low
Open the original source