Advisory: Pahalgam Attack themed decoys used by APT36 to target the Indian Government
April 30, 2025, 10 p.m.
Description
A Pakistan-linked APT group, Transparent Tribe (APT36), is targeting Indian Government and Defense personnel using 'Pahalgam Terror Attack' themed documents. The campaign involves credential phishing and deployment of malicious payloads, with fake domains impersonating Jammu & Kashmir Police and Indian Air Force. The phishing PDF documents contain embedded links leading to fake login pages. A PowerPoint add-on file with malicious macros has been identified, which drops the Crimson RAT payload. The campaign exploits sensitive geopolitical issues to maximize impact and extract intelligence. Multiple phishing domains were created shortly after the attack, impersonating various Indian government entities. The potential impact includes disruption of sensitive operations, information manipulation, and data breaches.
Tags
Date
- Created: April 30, 2025, 9:24 p.m.
- Published: April 30, 2025, 9:24 p.m.
- Modified: April 30, 2025, 10 p.m.
Indicators
- d1a1eaefe6bd2e245bba369e966d7a8eab9ed6ad1fa827321e5889cc8d43f976
- 6fcbcdcafc5accf1b2b0453eccd93c203ab1dca9920521b107c9cff8c0236eb2
- 486b535c91e8609867bce918693dd24f0d93437a710281ea65f34a9c088211ef
- 1d56e3fd6e8b45cf01b36cc95e35eb3644018231e528f4ac115c39c7e01e30ba
- 93.127.133.58
- 78.40.143.98
- 78.40.143.189
- 45.141.59.72
- 45.141.59.167
- 45.141.58.33
- 45.141.58.224
- 37.221.64.134
- 192.64.118.76
- 176.65.143.215
- 104.129.27.14
- 84.54.51.12
- indianarmy.nic.in.ministryofdefenceindia.org
- indianarmy.nic.in.departmentofdefence.de
- iaf.nic.in.ministryofdefenceindia.org
- email.gov.in.modindia.link
- email.gov.in.ministryofdefenceindia.org
- email.gov.in.indiandefence.work
- email.gov.in.indiadefencedepartment.link
- email.gov.in.drdosurvey.info
- email.gov.in.departmentofspace.info
- email.gov.in.departmentofdefenceindia.link
- email.gov.in.departmentofdefence.de
- email.gov.in.defenceindia.ltd
- email.gov.in.briefcases.email
Additional Informations
- Defense
- Government
- jkpolice.gov.in.kashmiraxxack.exposed
- jkpolice.gov.in.kashmirattack.exposed
- email.gov.in.indiangov.download
- kashmirattack.exposed
- India