Resource Development
1 technique·derived
Romance personas approaching military personnel.
Pakistani collection aimed almost exclusively at Indian military and government targets, increasingly through Android implants.
APT36 — commonly reported as Transparent Tribe — runs a narrowly focused collection programme against Indian military, paramilitary, government, and defence-research targets. It is one of the most single-minded actors tracked: essentially all documented activity serves Pakistani interests with respect to India.
The group's tradecraft is not sophisticated, but it is well matched to its targets. Lures reference Indian military documents, defence procurement notices, and government circulars with enough authenticity to suggest access to genuine material. Its flagship implant, Crimson RAT, has been in continuous use for years with incremental refinement rather than replacement.
Its most operationally interesting characteristic is the emphasis on mobile. The group builds Android implants — CapraRAT and its variants — and distributes them through fake dating applications, trojanised chat apps, and repackaged legitimate software aimed at military personnel. Several documented campaigns used romance-themed social engineering to persuade individual soldiers to install the applications, a route to communications, location, and camera access that no enterprise security programme covers.
More recently the group has expanded to Linux, targeting the BOSS distribution used by parts of the Indian government, and has adopted ClickFix-style lures that persuade users to paste commands into their own terminal.
Down to the named unit where public evidence supports it.
Assessed as aligned with Pakistani state interests by Proofpoint, Cisco Talos, Kaspersky, and Indian government reporting, based on exclusive targeting of Indian military and government entities, Pakistani-language and timezone artifacts, and infrastructure registration patterns. No formal government attribution has been issued and no individuals have been indicted.
Attributing sources
8 designators across 8 organisations.
1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.
TA### ('Threat Actor'), numbered sequentially in order of first tracking.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
The group's long-running .NET implant, supporting screenshots, file theft, webcam capture, and process control.
Malpedia ↗Android implant distributed via fake dating and messaging apps, providing access to messages, calls, location, and camera.
Malpedia ↗Windows backdoor delivered through malicious documents and, in some campaigns, steganographic payload hiding.
Malpedia ↗Golang implant targeting the BOSS Linux distribution used in parts of the Indian government.
Shared, commodity & living-off-the-land
Websites distributing trojanised Android applications aimed at military personnel.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT36 | ||
|---|---|---|---|---|
| CVE-2017-0199KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Mar 2018 | OLE2link RTF exploit delivering Crimson RAT in phishing against Indian defence targets.SRCCisco Talos ↗ |
| CVE-2012-0158KEV | 8.8 | Microsoft OfficeMicrosoft | 1 Jan 2016 | MSCOMCTL overflow used in early campaigns against Indian military targets.SRCProofpoint ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Romance personas approaching military personnel.
2 techniques·derived
Indian military and government document lures.
2 techniques·derived
Trojanised Android applications installed by targets themselves. ClickFix-style lures persuading users to run commands in their own terminal.
4 techniques·derived
USB monitoring to reach documents from isolated systems.
1 technique·derived
Web Protocols.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Romance personas approaching military personnel
Indian military and government document lures
Trojanised Android applications installed by targets themselves
ClickFix-style lures persuading users to run commands in their own terminal
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Direct regional adversaries — SideWinder targets Pakistani military and government, APT36 targets Indian.
Microsoft and Lumen documented Turla hijacking the C2 infrastructure of the related Storm-0156 cluster in 2024.
Curated links to the reports that established what is known about this group.