APT36 Campaign Uses LNK Files for Cyberespionage Against Indian Targets
First seen 6 Jan 2026, 02:27 UTC
•
•52.3
Export
Article Content
Browse articles
APT36, also known as Transparent Tribe, conducted a spear-phishing campaign targeting Indian government, strategic, and academic organizations. The campaign involved delivering malicious LNK files disguised as PDFs, which exploited mshta.exe to execute a remote HTA loader and deploy a fileless RAT. The malware adapts its persistence methods based on the victim's antivirus software.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Coordinated Cyberattack Disrupts Water Utilities in Minnesota
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
State-Linked Cyber Threats Intensify Amid AI Advancements
SideCopy Targets Afghanistan Finance Ministry with XenoRAT Campaign
Bitdefender Alerts on APT36's New AI 'Vibeware' Targeting India