216.73.216.6

Phishing Campaign Targets Indian Defense Using Credential-Stealing Malware

· Published 21/06/2025 14:51 · Modified 24/06/2025 14:27

Export JSON

Essential information

Published
21/06/2025 14:51
Modified
24/06/2025 14:27
Tags
2025-06-21 credential-theft cyber espionage indian defense pakistan pdf phishing transparent tribe
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 4 others

Description

APT36, a -based group, is actively targeting personnel through sophisticated campaigns. The group disseminates emails with malicious attachments resembling official government documents. When opened, these PDFs display a blurred background and a button mimicking the National Informatics Centre login interface. Clicking the button redirects users to a fraudulent URL and initiates the download of a ZIP archive containing a malicious executable disguised as a legitimate application. This campaign highlights APT36's focus on credential theft and long-term infiltration of networks, emphasizing the need for robust email security, user awareness programs, and proactive threat detection systems.

External references