Skip to content
PakistanState-SponsoredActiveMITRE G0134Malpedia ↗

APT36

Pakistani collection aimed almost exclusively at Indian military and government targets, increasingly through Android implants.

Open MITRE Navigator layer ↗Download profile JSON
Active
2013–present
Motivation
Espionage
Aliases
8
Exploited CVEs
2
ATT&CK techniques
10
Cited sources
7

Overview

APT36 — commonly reported as Transparent Tribe — runs a narrowly focused collection programme against Indian military, paramilitary, government, and defence-research targets. It is one of the most single-minded actors tracked: essentially all documented activity serves Pakistani interests with respect to India.

The group's tradecraft is not sophisticated, but it is well matched to its targets. Lures reference Indian military documents, defence procurement notices, and government circulars with enough authenticity to suggest access to genuine material. Its flagship implant, Crimson RAT, has been in continuous use for years with incremental refinement rather than replacement.

Its most operationally interesting characteristic is the emphasis on mobile. The group builds Android implants — CapraRAT and its variants — and distributes them through fake dating applications, trojanised chat apps, and repackaged legitimate software aimed at military personnel. Several documented campaigns used romance-themed social engineering to persuade individual soldiers to install the applications, a route to communications, location, and camera access that no enterprise security programme covers.

More recently the group has expanded to Linux, targeting the BOSS distribution used by parts of the Indian government, and has adopted ClickFix-style lures that persuade users to paste commands into their own terminal.

Attribution

Down to the named unit where public evidence supports it.

PakistanPakistani state interests (specific service not publicly designated)Moderate confidence

Assessed as aligned with Pakistani state interests by Proofpoint, Cisco Talos, Kaspersky, and Indian government reporting, based on exclusive targeting of Indian military and government entities, Pakistani-language and timezone artifacts, and infrastructure registration patterns. No formal government attribution has been issued and no individuals have been indicted.

Attributing sources

Cross-vendor naming crosswalk

8 designators across 8 organisations.

1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • Transparent Tribe

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Storm-0156partialMicrosoft's cluster for related Pakistani activity, whose infrastructure Turla was documented hijacking in 2024

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Mythic Leopard

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Secureworks CTU

index ↗
  • ALUMINUM SARATOGA

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Kaspersky GReAT

index ↗
  • Transparent Tribe

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Trend Micro

index ↗
  • Earth Karkaddan

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

Proofpoint

index ↗
  • Operation C-Major

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

CISA / NSA / FBI

index ↗
  • APT36

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

IndiaAfghanistanNepalSri Lanka

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Crimson RATbackdoor

The group's long-running .NET implant, supporting screenshots, file theft, webcam capture, and process control.

Malpedia ↗
CapraRATmalware

Android implant distributed via fake dating and messaging apps, providing access to messages, calls, location, and camera.

Malpedia ↗
ObliqueRATbackdoor

Windows backdoor delivered through malicious documents and, in some campaigns, steganographic payload hiding.

Malpedia ↗
Poseidonbackdoor

Golang implant targeting the BOSS Linux distribution used in parts of the Indian government.

Shared, commodity & living-off-the-land

Fake app storesutility

Websites distributing trojanised Android applications aimed at military personnel.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT36
CVE-2017-0199KEVransomware7.81 Mar 2018OLE2link RTF exploit delivering Crimson RAT in phishing against Indian defence targets.SRCCisco Talos
CVE-2012-0158KEV8.81 Jan 2016MSCOMCTL overflow used in early campaigns against Indian military targets.SRCProofpoint

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

5 stages · 10 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 5 tactics · 5 with actor-specific notes

Resource Development

1

Initial Access

2

Execution

2

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.