Categories: Cyber Security News

TransparentTribe Targets Linux Systems in Indian Military Networks to Deploy DeskRAT

This article should read as a concise cybersecurity news piece summarizing a sophisticated APT campaign by TransparentTribe (APT36) targeting Indian defense systems running BOSS Linux. Here’s the full write-up:

TransparentTribe Targets Linux Systems

In a significant escalation of cross-border cyber-espionage activity, researchers have uncovered a new campaign by the Pakistan-linked threat actor TransparentTribe (APT36) targeting Linux-based systems used by Indian defense and government entities.

The operation, active since June 2025, delivers a Golang-based Remote Access Trojan (DeskRAT) through weaponized .desktop files embedded in phishing campaigns.

Evolution of the Infection Chain

According to joint analyses by CYFIRMA and Sekoia.io, the attack begins with phishing emails containing malicious ZIP archives masquerading as official defense communications.

These archives—such as Cyber-Security-Advisory.zip or MoM_regarding_Defence_Sectors_by_Secy_Defence_25_Sep_2025.zip—contain malicious .desktop files designed to exploit BOSS Linux, India’s government-endorsed operating system.

Infection chain leading to the installation of DeskRAT

When executed, the shortcut file silently runs Bash one-liners that download base64-encoded payloads from attacker-controlled domains like modgovindia[.]com.

The payload is decoded, written into the /tmp/ directory, granted executable permissions, and launched in the background. Simultaneously, a decoy document, often a defense-related PDF, is opened using Firefox to distract the victim.

The technique leverages built-in Linux utilities such as curl, base64, and eval, minimizing dependencies and bypassing typical detection mechanisms. Earlier versions of the campaign used Google Drive links to distribute the payloads, but recent samples indicate a move toward dedicated staging servers, enhancing control and persistence.

DeskRAT: Golang-Based Espionage Tool

The final stage deploys DeskRAT, a custom Golang remote administration tool engineered for Linux environments.

Analysis of the sample (MD5: 3563518ef8389c7c7ac2a80984a2c4cd) reveals modular functions suggesting LLM-assisted development, with several fake “evasion” routines embedded to waste analyst time and confuse detection systems.

Once executed, DeskRAT establishes WebSocket-based command and control communications with servers such as seeconnectionalive[.]website and newforsomething[.]rest on port 8080.

Execution pop-up of a DESKTOP file on a BOSS Desktop distribution

The malware can browse files, exfiltrate data, execute remote commands, and upload additional payloads, offering operators complete control over infected machines.

The C2 infrastructure features a web-based “Advanced Client Monitoring & File Management System” interface used to manage compromised hosts, monitor real-time telemetry, and execute post-exploitation actions.

The campaign timing aligns with political unrest in the Ladakh and New Delhi regions, events that APT36 has seemingly exploited to enhance phishing credibility. Analysts are highly confident that these intrusions serve Pakistan’s strategic intelligence objectives, focusing primarily on Indian defense institutions.

Security researchers warn that TransparentTribe’s evolution from Windows to Linux espionage operations underscores a dangerous shift in threat actor sophistication.

Defense networks relying on BOSS Linux should reinforce email filtering, system hardening, and real-time monitoring to mitigate exposure to future campaigns.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post TransparentTribe Targets Linux Systems in Indian Military Networks to Deploy DeskRAT appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Here’s Every Star Wars Movie and TV Show You Can Buy in 4K UHD

Star Wars projects are at an all-time high, with The Mandalorian and Grogu set to…

2 hours ago

The Best Deals Today: Castlevania Blu-ray Box Set, Dragon Quest VII Reimagined, LEGO Project Hail Mary, and More

A new weekend has arrived, and today, you can save big on Castlevania: The Complete…

6 hours ago

Minecraft Dungeons 2 Revealed With Fall 2026 Launch

Mojang Studios has officially announced that Minecraft Dungeons 2 is in development with plans to…

7 hours ago

Mojang Reveals Chaos Cubed Update Coming to Minecraft Later This Year With Tiny Takeover Release Date Set for Next Week

Mojang Studios has unveiled more information about updates coming to Minecraft in 2026, including the…

7 hours ago

Minecraft World Concept Art Reveals New Theme Park Coming in 2027

Minecraft World, a theme park based on the video game from Mojang Studios, will officially…

7 hours ago

Man caught exposing himself in Concord apartment complex faces multiple charges

Concord police arrested a man they say was exposing himself in a private apartment complex.…

7 hours ago

This website uses cookies.