A politically motivated advanced persistent threat group has expanded its malware arsenal to include a new remote access trojan in its espionage attacks aimed at Indian military and diplomatic entities.
The malware dubbed CapraRAT by Trend Micro is an Android RAT that exhibits a high “degree of crossover” with another Windows malware known as CrimsonRAT which is associated with Earth Karkaddan, a threat actor with monikers APT36, Operation C-Major, PROJECTM, Mythic Leopard, and Transparent Tribe.
The first signs of APT36’s existence appeared in 2016 when the group began distributing information-stealing malware through phishing emails with malicious PDF attachments targeting Indian military and government personnel. The group which has been operational since at least 2013 is believed to be of Pakistani origin.
The modus operandi of the threat actor include attacks predominantly banking on social engineering and a USB-based worm as entry points. Among common elements in the group’s arsenal is a Windows backdoor called CrimsonRAT that allows the attackers extensive access to compromised systems, although recent campaigns have evolved to deliver ObliqueRAT.
CrimsonRAT is fashioned as a .NET binary whose main aim is to obtain and exfiltrate information from targeted Windows systems, including screenshots, keystrokes, and files from removable drives, and upload them to the attacker’s command-and-control server.
The new malware is another custom Android RAT that’s deployed by means of phishing links. CapraRAT, which is disguised as a YouTube app, is said to be a modified version of an open-source RAT called AndroRAT and comes with a variety of data exfiltration functions, including the ability to harvest victims’ locations, phone logs, and contact information.
In order to mitigate attacks, users are advised to watch out for unsolicited emails, avoid clicking on links or downloading email attachments from unknown senders, install apps only from trusted sources, and be cautious while granting permissions requested by the apps.

















Comments