216.73.216.6

TransparentTribe Targets Indian Military with DeskRAT Malware

· Published 23/10/2025 21:49 · Modified 24/10/2025 09:21

Export JSON

Essential information

Published
23/10/2025 21:49
Modified
24/10/2025 09:21
Tags
2025-10-23 deskrat government
Related entities
1 intrusion sets (apt), 18 techniques (mitre), 1 malware, 4 others

Description

TransparentTribe, a Pakistani-nexus intrusion set, has launched a new cyber espionage campaign targeting Indian military organizations with malware. The infection chain begins with phishing emails containing links to malicious ZIP archives hosted on staging servers. These archives contain DESKTOP files that execute a multi-stage payload, ultimately delivering a Golang-based Remote Access Trojan (RAT) dubbed . The malware establishes command and control communications over WebSocket and implements various persistence techniques specific to Linux environments. The campaign appears to be designed to target BOSS operating systems, endorsed by the Indian . TransparentTribe leverages local protests and regional tensions to compromise defense and entities, aligning with their previous cyber espionage operations supporting Pakistan's strategic objectives in the region.

External references