216.73.217.22

A Phishing Campaign Targeting Indian Government Entities

· Published 03/08/2025 04:27 · Modified 04/08/2025 09:19

Export JSON

Essential information

Published
03/08/2025 04:27
Modified
04/08/2025 09:19
Tags
2025-08-03 credential harvesting defense government india kavach otp pakistan phishing typosquatting
Related entities
2 observables, 1 intrusion sets (apt), 13 techniques (mitre), 5 others

Description

A sophisticated campaign, likely attributed to -linked APT36 (Transparent Tribe), is targeting Indian organizations and entities using spoofed domains. The attackers employ advanced social engineering techniques, including real-time harvesting, to bypass multi-factor authentication and gain access to official email accounts. The campaign uses typo-squatted domains mimicking platforms to steal credentials. Infrastructure analysis reveals connections to Pakistani IPs and possible staging via Zah Computers. The threat actors create a false sense of legitimacy by referencing trusted authorities and secure communication flows. This coordinated approach highlights the severity of the threat and the attackers' strategic intent, potentially posing significant risks to national security.

External references