216.73.216.6

New year, new sector: Targeting India's startup ecosystem

· Published 04/02/2026 15:57 · Modified 04/02/2026 21:20

Export JSON

Essential information

Published
04/02/2026 15:57
Modified
04/02/2026 21:20
Tags
2026-02-04 apt36 crimson rat cybersecurity india iso lnk osint spear-phishing startup
Related entities
2 observables, 1 intrusion sets (apt), 19 techniques (mitre), 1 malware, 5 others

Description

Transparent Tribe, also known as , has expanded its targeting to include 's ecosystem, particularly those in the domain. The group is using -oriented themed lure material delivered via container-based files to deploy . This campaign deviates from their typical government and defense targets, suggesting a shift in strategy towards companies providing open-source intelligence services and collaborating with law enforcement agencies. The attack chain involves emails, malicious files, and batch scripts to execute the payload. The malware employs extensive obfuscation techniques and uses a custom TCP protocol for command and control communications. This activity demonstrates the group's adaptation of proven tooling for new victim profiles while maintaining its core behavioral tactics, techniques, and procedures.

External references