Categories: Cyber Security News

APT36 Targets Indian Government Systems Using Malicious Windows LNK Files

CYFIRMA researchers have uncovered a sophisticated cyber-espionage campaign launched by APT36 (Transparent Tribe), a Pakistan-linked threat actor known for targeting Indian government, academic, and defense entities.

The attackers are deploying a weaponized Windows shortcut (LNK) file masquerading as a genuine PDF document to compromise victims’ systems and enable covert data theft and surveillance.

Malicious LNK File Delivers Fileless RAT

The campaign begins with spear-phishing emails containing ZIP archives titled “Online JLPT Exam Dec 2025.zip.” Within the archive lies a deceptive file named “Online JLPT Exam Dec 2025.pdf.lnk,” designed to appear as a legitimate PDF.

Unlike typical shortcuts (10–12 KB), the malicious LNK file exceeds 2 MB and embeds a full PDF to reduce user suspicion.

When executed, the shortcut abuses the legitimate Windows binary mshta.exe to fetch and run a remote HTA script from innlive[.]in.

This HTA loader operates invisibly, decrypting and executing multiple payloads directly in memory, an advanced “fileless” execution technique that evades traditional antivirus detection.

The staged chain loads two encrypted objects, ReadOnly and WriteOnly, with WriteOnly executing a malicious DLL that functions as a Remote Access Trojan (RAT).

Adaptive Malware and Persistent Access

The analyzed DLLs, ki2mtmkl.dll and iinneldc.dll, enable complete remote control of compromised systems.

Once activated, they establish encrypted Command-and-Control (C2) communication with IP 2.56.10[.]86 over TCP port 8621, exfiltrating system details like username, OS version, and installed antivirus software.

The malware can execute remote shell commands, capture screenshots, monitor clipboard activity, manage files, and steal sensitive documents, including Office files and PDFs.

One standout feature of this campaign is its antivirus-aware persistence mechanism. The malware queries Windows Management Instrumentation (WMI) to detect installed security tools and adapt accordingly.

For instance, when Kaspersky is detected, it stores payloads in C:UsersPubliccore and gains persistence via startup shortcuts.

With other antivirus tools, such as Quick Heal or Avast, it alters its methods, creating batch files or registry entries to maintain access.

The campaign’s infrastructure also includes decoy PDFs and multiple fallback payloads, ensuring execution reliability and stealth. All exfiltrated data is Base64-encoded and AES-encrypted before transmission, maintaining confidentiality during network communication.

CYFIRMA attributes this operation to APT36’s continuing espionage focus, emphasizing intelligence gathering over financial gain.

Experts note the actor’s increased sophistication through living-off-the-land techniques, environment-aware persistence, and fileless payload delivery.

Security teams are advised to block LNK attachments, restrict the execution of mshta.exe, and monitor traffic to suspicious domains and IP addresses, such as innlive[.]in, drjagrutichavan[.]com, and 2.56.10[.]86.

Behavior-based defenses and continuous monitoring remain critical against such evolving state-aligned intrusion campaigns.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post APT36 Targets Indian Government Systems Using Malicious Windows LNK Files appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

The iBuyPower Limited Edition Honkai Star Rail “Firefly” Prebuilt Gaming PC Is Now Available

For all of you Honkai Star Rail superfans, there's a custom PC built just for…

4 minutes ago

The Live Nation trial restarts with a ‘velvet hammer’

After a chaotic week following the Justice Department's mid-trial settlement with Live Nation-Ticketmaster, the antitrust…

54 minutes ago

AliExpress Has a 1,000W Peak 48V Adult Electric Bike for $287.60 (or Less) With Free Delivery

Looking for a powerful ebike with the speed and range to meet your ambitious needs?…

2 hours ago

The GRUV 3-for-$30 4K Blu-Ray Movie Sale Starts Today With Over 250 Movies to Choose From

Don't miss this great opportunity to add to your 4K movie collection. Gruv, one of…

2 hours ago

Trump probe of Fed Chair Powell meant to harass, judge says while denying subpoenas

Federal Reserve Chair Jerome Powell speaks during a press conference on Dec. 10, 2025 in…

2 hours ago

Trump probe of Fed Chair Powell meant to harass, judge says while denying subpoenas

Federal Reserve Chair Jerome Powell speaks during a press conference on Dec. 10, 2025 in…

2 hours ago

This website uses cookies.