The Transparent Tribe Vibe: APT36 Returns With CapraRAT Impersonating Viber
Essential information
- Published
- 03/06/2025 18:25
- Modified
- 03/06/2025 21:16
- Tags
- 2025-06-03 android androrat caprarat contabo crimson rat impersonation spyware transparent tribe viber vps
- Related entities
- 3 observables, 1 intrusion sets (apt), 2 techniques (mitre), 3 malware
Description
APT36, also known as Transparent Tribe, has been observed using VPS provider Contabo to host malicious infrastructure for CapraRAT and Crimson RAT. Their latest tactic involves disguising spyware as the popular messaging app Viber, granting extensive permissions to record calls, read messages, and track location. The investigation traced the infrastructure, identified key Indicators of Compromise, and uncovered the full extent of this Android surveillance campaign. The threat actor employs social engineering tactics to distribute their Android Remote Access Trojans, with lures crafted to align with the RAT's disguise. The malware's capabilities include targeted surveillance, credential theft, and infrastructure abuse, potentially eroding brand trust in legitimate communication platforms.