Transparent Tribe Targets India’s Startup Ecosystem In Renewed Cyber Espionage Campaign

Transparent Tribe, a Pakistan-linked cyber espionage group known as APT36, has expanded its attacks to target India’s burgeoning startup ecosystem, particularly cybersecurity firms.

Acronis Threat Research Unit (TRU) detailed this campaign in a February 2026 report, noting the use of Crimson RAT malware delivered via tailored phishing.​

Transparent Tribe has operated since 2013, focusing on South Asian nations like India and Afghanistan.

The group typically uses social engineering lures themed around government, defense, education, and military events to spy on officials and organizations.

It deploys simple payloads, such as malicious LNK files, ISO containers, HTA scripts, and ZIP archives, often dropping remote access trojans such as Crimson RAT or GymRAT.

This new activity marks a deviation, hitting startups in open-source intelligence (OSINT) and cybersecurity. TRU attributes it to Transparent Tribe with high confidence due to matching malware, infrastructure, and tactics from prior campaigns since October 2025.

Campaigns start with spear-phishing emails containing ISO files like “MeetBisht.iso,” named after a startup founder’s name for credibility.

Opening the ISO reveals a fake Excel shortcut (“Meet Bisht.xlsx.lnk”), a decoy document, a batch runner script (“mycsd.bat”), and the Crimson RAT payload disguised as “excel.exe.”​

The LNK launches the batch file via a minimized command prompt, which shows the decoy while copying files to C:\ProgramData\ and %APPDATA%. It uses PowerShell to strip Mark of the Web flags, evading SmartScreen, then runs the RAT stealthily.​

Contents inside the malicious container-based payload (Source: acronis)
Contents inside the malicious container-based payload (Source: acronis)

Decoys reference real startups like Voldebug, which offers OSINT tools for SIS law enforcement use. This suggests attackers seek intelligence on firms aiding Indian government security efforts.​

Crimson RAT Breakdown

Crimson RAT is a bloated .NET trojan at 34MB, padded with junk data to dodge scanners and analysis limits. Its core code is tiny (80-150KB), hidden behind randomized names, obfuscated strings, and a custom TCP protocol over hardcoded C&C servers such as 93.127.133.9:443.​

Decoy-extracted shows data about the Director of Voldebug (Source: acronis)
Decoy-extracted shows data about the Director of Voldebug (Source: acronis)

The RAT grabs system info, usernames, AV details, and network data. It enables screen recording, webcam streaming, mic audio capture, file searches/transfers/deletions, process killing, and command execution.

Properties of the LNK file (Source: acronis)
Properties of the LNK file (Source: acronis)
CapabilityDescription
SurveillanceScreen capture, webcam, microphone recording
File OperationsList drives, search/upload/download/delete files
System ReconOS version, user privileges, security software
Process ControlList/kill processes, run commands/tools

Infrastructure and Attribution

C&C ties to past Transparent Tribe ops, including domain certstorein.shop used in government attacks with GymRAT. Pivots on filenames like “Evidance.pdf.lnk” (misspelled “Evidence”) link to other lures.​

Code snippet about screen capturing functionality (Source: acronis)
Code snippet about screen capturing functionality (Source: acronis)

India-uploaded samples on VirusTotal show consistent TTPs. Acronis EDR/XDR blocks it.

IoC TypeValueDescription
ISO5c4488b4eda72d245dac5382f3587f09MeetBisht.iso
LNK4976ef0054b0283c0d013be2f442e17bMalicious shortcut
RAT5b4a48815446cd40d8e141cbf8582296Crimson RAT (Excel.exe)
Batch22218f19425b78dfd6a4f42e43f5486fRunner script
C&C IP93.127.133.9Main server

This pivot highlights startups as fresh espionage prizes, given their government ties. Defenders should scan ISO/LNK files, monitor unusual batch/PowerShell activity, and block listed IoCs.

Transparent Tribe’s reuse of tools shows evolution, not reinvention, urging vigilance in India’s tech sector.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories