Phishing Attack: Deploying Malware on Indian Defense BOSS Linux
Aug. 10, 2025, 9:44 p.m.
Description
APT36, a Pakistan-based threat actor, has launched a sophisticated cyber-espionage campaign targeting the Indian defense sector. The group has adapted its tactics to focus on Linux-based environments, particularly BOSS Linux, used by Indian government agencies. The attack involves phishing emails with a ZIP file containing a malicious .desktop file. When executed, it downloads a legitimate PowerPoint file as a decoy while simultaneously deploying a malicious ELF binary. This multi-stage approach aims to bypass user suspicion and evade traditional security measures. The campaign signifies an advancement in APT36's capabilities and poses an increased risk to critical government and defense infrastructure. Organizations using Linux-based systems are advised to implement robust cybersecurity controls and threat detection mechanisms to mitigate potential risks.
Tags
Date
- Created: Aug. 8, 2025, 5:08 p.m.
- Published: Aug. 8, 2025, 5:08 p.m.
- Modified: Aug. 10, 2025, 9:44 p.m.
Indicators
- e528799a29e9048c1e71b78223311cad2699d035a731d1a6664fc8ddd0642064
- ace379265be7f848d512b27d6ca95e43cef46a81dc15d1ad92ec6f494eed42ab
- 608fff2cd4b727799be762b95d497059a202991eb3401a55438071421b9b5e7a
- 167b387005d6d2a55ad282273c58d1786a2ee0fa3e7e0cb361d4d61d8618ee5f
- 101.99.92.182
- govin.sorlastore.com
- modgovin.onthewifi.com
- sorlastore.com
Additional Informations
- Defense
- Government
- India