Cyber Hacking News

Pakistani hackers target Indian students in new malware campaign

0

The advanced persistent threat group called Transparent Tribe has been attributed to a new ongoing phishing campaign targeting students at various educational institutions in India at least since December 2021.

According to a report by Cisco Talos, the APT is actively expanding its network of victims to include civilian users.

The hacker group also known by the names APT36, Operation C-Major, PROJECTM and Mythic Leopard, is suspected to be of Pakistani origin and is known to strike government entities and think tanks in India and Afghanistan with custom malware such as CrimsonRAT, ObliqueRAT, and CapraRAT.

The targeting of educational institutions and students, first observed by India-based K7 Labs in May 2022, indicates a deviation from the adversary’s typical focus.

The researchers stated that the APTs will frequently target individuals at universities and technical research organizations in order to establish long term access to siphon off data related to ongoing research projects.

The threat actors send a maldoc to the targets either as an attachment or a link to a remote location via a spear-phishing email, ultimately leading to the deployment of CrimsonRAT.

Transparent Tribes’ email lures look legitimate with appropriate content to convince the targets into opening the maldocs or visiting the malicious links provided.

CrimsonRAT, also known as SEEDOOR and Scarimson, are used by the threat actor to establish long-term access into victim networks and also to exfiltrate data of interest to a remote server.

The malware allows the attackers to remotely control the infected machine, steal browser credentials, record keystrokes, capture screenshots, and execute arbitrary commands.

Several of these decoy documents were hosted on education-themed domains that were registered as early as June 2021, with the infrastructure operated by a Pakistani web hosting services provider named Zain Hosting.

However, the researchers concluded that the entire scope of Zain Hosting’s role in the Transparent Tribe organization is still unknown. This might be one of many third-parties, Transparent Tribe employs to prepare, stage or deploy components of their operation.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

‘Callback’ phishing campaign impersonates cyber security firms

Previous article

Bandai Namco confirms hack after ransomware data leak threat

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *