216.73.216.108

Illuminating Transparent Tribe

· Published 03/06/2025 18:25 · Modified 03/06/2025 21:13

Export JSON

Essential information

Published
03/06/2025 18:25
Modified
03/06/2025 21:13
Tags
2025-06-03 apt36 defense dns history etag pivoting indian government infrastructure discovery passive dns phishing
Related entities
3 observables, 1 intrusion sets (apt), 5 techniques (mitre), 6 others

Description

This analysis explores the infrastructure of , also known as Transparent Tribe, using and host response history. Starting with indicators from a CyberXTron report on a targeted attack against and , the investigation expands through , IP pivoting, and host response analysis. Key findings include shared name server patterns, non-Cloudflare IP addresses, and connections to previously unreported domains. The research identifies potential new infrastructure using , revealing domains with similar subdomain conventions to known Transparent Tribe assets. The methodology demonstrates the power of comprehensive DNS data and host response history in uncovering hidden connections and potential threat infrastructure.

External references