Transparent Tribe, a Pakistan-linked cyber espionage group known as APT36, has expanded its attacks to target India’s burgeoning startup ecosystem, particularly cybersecurity firms.
Acronis Threat Research Unit (TRU) detailed this campaign in a February 2026 report, noting the use of Crimson RAT malware delivered via tailored phishing.
Transparent Tribe has operated since 2013, focusing on South Asian nations like India and Afghanistan.
The group typically uses social engineering lures themed around government, defense, education, and military events to spy on officials and organizations.
It deploys simple payloads, such as malicious LNK files, ISO containers, HTA scripts, and ZIP archives, often dropping remote access trojans such as Crimson RAT or GymRAT.
This new activity marks a deviation, hitting startups in open-source intelligence (OSINT) and cybersecurity. TRU attributes it to Transparent Tribe with high confidence due to matching malware, infrastructure, and tactics from prior campaigns since October 2025.
Campaigns start with spear-phishing emails containing ISO files like “MeetBisht.iso,” named after a startup founder’s name for credibility.
Opening the ISO reveals a fake Excel shortcut (“Meet Bisht.xlsx.lnk”), a decoy document, a batch runner script (“mycsd.bat”), and the Crimson RAT payload disguised as “excel.exe.”
The LNK launches the batch file via a minimized command prompt, which shows the decoy while copying files to C:\ProgramData\ and %APPDATA%. It uses PowerShell to strip Mark of the Web flags, evading SmartScreen, then runs the RAT stealthily.

Decoys reference real startups like Voldebug, which offers OSINT tools for SIS law enforcement use. This suggests attackers seek intelligence on firms aiding Indian government security efforts.
Crimson RAT Breakdown
Crimson RAT is a bloated .NET trojan at 34MB, padded with junk data to dodge scanners and analysis limits. Its core code is tiny (80-150KB), hidden behind randomized names, obfuscated strings, and a custom TCP protocol over hardcoded C&C servers such as 93.127.133.9:443.

The RAT grabs system info, usernames, AV details, and network data. It enables screen recording, webcam streaming, mic audio capture, file searches/transfers/deletions, process killing, and command execution.

Infrastructure and Attribution
C&C ties to past Transparent Tribe ops, including domain certstorein.shop used in government attacks with GymRAT. Pivots on filenames like “Evidance.pdf.lnk” (misspelled “Evidence”) link to other lures.

India-uploaded samples on VirusTotal show consistent TTPs. Acronis EDR/XDR blocks it.
This pivot highlights startups as fresh espionage prizes, given their government ties. Defenders should scan ISO/LNK files, monitor unusual batch/PowerShell activity, and block listed IoCs.
Transparent Tribe’s reuse of tools shows evolution, not reinvention, urging vigilance in India’s tech sector.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.