Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by CYFIRMA. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by CYFIRMA or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

CYFIRMA Research- APT36 Python Based ELF Malware Targeting Indian Government Entities

4:46
 
Share
 

Manage episode 523741600 series 3472819
Content provided by CYFIRMA. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by CYFIRMA or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

APT36 Targets Indian Government Entities with a New Python-Based ELF Malware.
CYFIRMA has uncovered a new cyber-espionage campaign by APT36 (Transparent Tribe), a Pakistan-based threat actor long known for targeting Indian government entities and strategic sectors.
This campaign showcases a major leap in the group’s technical sophistication — delivering custom Python-based ELF malware through weaponized .desktop shortcut files distributed via spear-phishing.
📌 Key Highlights:
The campaign begins with a malicious ZIP file containing a deceptive .desktop shortcut.
Once executed, the shortcut downloads:
A decoy PDF to distract the user
A malicious ELF payload (swcbc)
A persistence-enabling shell script (swcbc.sh)

The malware establishes C2 communication, executes shell/Python commands, steals files, takes screenshots, and maintains persistence.

Infrastructure used includes Lionsdenim[.]xyz and 185.235.137.90, both tied to APT36’s ongoing espionage operations.

The ELF implant is a PyInstaller-packed RAT, supporting cross-platform execution on both Linux and Windows.

Link to the Research Report: APT36 Python Based ELF Malware Targeting Indian Government Entities - CYFIRMA
#CyberSecurity #ThreatIntel #APT36 #MalwareAnalysis #IndianGovernment #LinuxMalware #CYFIRMA #CyberEspionage #ThreatResearch #ELFMalware #PyInstaller #TransparentTribe #ExternalThreatLandscapeManagement

https://www.cyfirma.com/

  continue reading

268 episodes

Artwork
iconShare
 
Manage episode 523741600 series 3472819
Content provided by CYFIRMA. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by CYFIRMA or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

APT36 Targets Indian Government Entities with a New Python-Based ELF Malware.
CYFIRMA has uncovered a new cyber-espionage campaign by APT36 (Transparent Tribe), a Pakistan-based threat actor long known for targeting Indian government entities and strategic sectors.
This campaign showcases a major leap in the group’s technical sophistication — delivering custom Python-based ELF malware through weaponized .desktop shortcut files distributed via spear-phishing.
📌 Key Highlights:
The campaign begins with a malicious ZIP file containing a deceptive .desktop shortcut.
Once executed, the shortcut downloads:
A decoy PDF to distract the user
A malicious ELF payload (swcbc)
A persistence-enabling shell script (swcbc.sh)

The malware establishes C2 communication, executes shell/Python commands, steals files, takes screenshots, and maintains persistence.

Infrastructure used includes Lionsdenim[.]xyz and 185.235.137.90, both tied to APT36’s ongoing espionage operations.

The ELF implant is a PyInstaller-packed RAT, supporting cross-platform execution on both Linux and Windows.

Link to the Research Report: APT36 Python Based ELF Malware Targeting Indian Government Entities - CYFIRMA
#CyberSecurity #ThreatIntel #APT36 #MalwareAnalysis #IndianGovernment #LinuxMalware #CYFIRMA #CyberEspionage #ThreatResearch #ELFMalware #PyInstaller #TransparentTribe #ExternalThreatLandscapeManagement

https://www.cyfirma.com/

  continue reading

268 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play