216.73.217.22

APT36: Targets Indian BOSS Linux Systems with Weaponized AutoStart Files

· Published 23/08/2025 10:33 · Modified 25/08/2025 11:03

Export JSON

Essential information

Published
23/08/2025 10:33
Modified
25/08/2025 11:03
Tags
2025-08-23 boss linux cyber espionage desktop files elf government india pakistan persistence spear-phishing
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 3 others

Description

APT36, a -based threat actor, is conducting a cyber-espionage campaign against Indian entities, targeting systems with weaponized .. The group uses emails to deliver malicious payloads, exploiting the Linux environment to maintain persistent access and evade security controls. The campaign involves sophisticated tactics, including the use of custom malware, command and control servers, and data exfiltration techniques. The attackers leverage newly registered domains and employ various MITRE ATT&CK techniques to execute their operations. This activity demonstrates APT36's increasing sophistication and adaptability in targeting critical infrastructure.

External references