- Target Sectors
- Government, Defense, Military, Diplomatic, Research, Education, Aerospace, Critical Infrastructure, Cybersecurity Startups, OSINT Firms
- Associated Malware
- Crimson RAT, CapraRAT, ObliqueRAT, ElizaRAT, ApoloStealer, njRAT, Limepad, GETA RAT, ARES RAT, Desk RAT
Overview
Transparent Tribe, tracked by MITRE ATT&CK as G0134, is a prolific and persistent advanced persistent threat (APT) group believed to operate out of Pakistan. Active since at least 2013, this group, also known by aliases such as COPPER FIELDSTONE, APT36, Mythic Leopard, and ProjectM, has consistently focused its efforts on cyber espionage and information theft. While often not considered highly sophisticated in its initial tradecraft, Transparent Tribe is remarkably adaptive, regularly updating its operational strategies, tools, and targeting to maintain access and evade detection.
The group’s primary objective is intelligence collection, with a clear and unwavering focus on targets within India and, to a lesser extent, Afghanistan. Historically, their campaigns have centered on Indian government organizations, military personnel, defense contractors, and diplomatic entities. However, recent activity demonstrates a significant expansion of their targeting profile to include the Indian education sector, research centers, critical infrastructure, and notably, the burgeoning startup ecosystem, particularly those involved in cybersecurity and open-source intelligence (OSINT). This strategic shift suggests a broader intelligence mandate, aiming to compromise entities with operational proximity to government, law enforcement, and security functions. Transparent Tribe’s operations often align with heightened geopolitical tensions between India and Pakistan, implying a strategic motive behind their activities.
Tactics & Techniques
Transparent Tribe heavily relies on social engineering, primarily spear-phishing, as its initial access vector. These phishing campaigns often leverage meticulously crafted lures that exploit current events, geopolitical themes (like the Kashmir conflict or terror attacks), or emotionally charged subjects to increase the likelihood of compromise. They frequently use malicious attachments disguised as legitimate documents (e.g., Microsoft Word, PowerPoint, Excel files) containing macros, or more recently, weaponized Windows shortcut (LNK) files, ISO container files, CPL files, and ZIP archives. These files, once opened, initiate multi-stage infection chains that can involve legitimate Windows binaries like mshta.exe for in-memory execution or PowerShell to strip “Mark of the Web” flags to evade SmartScreen.
A consistent tactic involves creating fake or typo-squatted domains that mimic legitimate government websites, educational institutions, or popular services like India’s Kavach multi-factor authentication portal and National Informatics Centre (NIC) eMail Services. They have also been observed using malvertising campaigns, abusing platforms like Google Ads to promote these malicious domains and drive targeted traffic. For distribution and command-and-control (C2), the group frequently abuses legitimate web services, including Google Drive, Telegram, Discord, and Slack, to host malicious files and facilitate communication, making detection challenging.
Transparent Tribe demonstrates an evolving technical proficiency, incorporating cross-platform programming languages like Python, Golang, and Rust to develop tools capable of targeting Windows, Android, and Linux environments, including India’s indigenous Bharat Operating System Solutions (BOSS) Linux. Their defense evasion techniques include fileless payload strategies, obfuscation (such as Eazfuscator), and exploiting known vulnerabilities like CVE-2012-0158 and CVE-2010-3333 to deliver their malware. Persistence is often achieved through mechanisms like systemd user services for Linux or by installing their remote access trojans (RATs).
Notable Campaigns
Transparent Tribe has maintained a high operational tempo since its inception. Early reporting by Proofpoint in 2016 highlighted “Operation Transparent Tribe,” which targeted Indian diplomatic and military resources, including embassies in Saudi Arabia and Kazakhstan. Trend Micro’s “Operation C-Major” also detailed spear-phishing attacks against Indian military officials, leveraging an Adobe Reader vulnerability. They have also impersonated Indian think tanks to target officials within the Central Bureau of Investigation (CBI) and the Indian Army.
More recent campaigns underscore their continuous adaptation. In 2022, they were observed using new bespoke stagers and implants while still heavily relying on their staple Crimson RAT, often distributed through executables masquerading as legitimate installers, archive files, and maldocs. From late 2023 through early 2026, Transparent Tribe has launched multiple campaigns demonstrating an expanded scope. These include intense targeting of the Indian education sector, government, defense, and aerospace sectors using sophisticated spear-phishing and LNK malware. Notable examples include phishing campaigns themed around the April 2025 Pahalgam terror attack, malvertising for the Kavach MFA application to steal credentials, and leveraging “NIC eEmail Services” themes. Their targeting of India’s startup ecosystem in early 2026, particularly cybersecurity and OSINT firms, involved startup-themed spear-phishing lures delivered via ISO files, leading to Crimson RAT deployment.
Associated Malware & Tools
Transparent Tribe has an extensive and evolving arsenal of malware, with Remote Access Trojans (RATs) forming the core of their capabilities for espionage. The group’s most consistently used and developed malware is Crimson RAT, a custom .NET-based implant that has been a staple since at least 2020 and frequently updated with enhanced evasion features. Crimson RAT is a full-featured RAT capable of keylogging, remote desktop manipulation, file management, audio/video surveillance, screenshot capture, command execution, and password theft.
Other prominent RATs in their toolkit include:
- ObliqueRAT: A C/C++-based RAT observed since at least 2020, used for arbitrary command execution and file exfiltration.
- ElizaRAT: A Windows RAT first disclosed in September 2023, which has evolved significantly in its execution, detection evasion, and C2 communication, often leveraging Slack and Telegram.
- CapraRAT: A modified Android RAT, an iteration of AndroRAT, mirroring many functionalities of Crimson RAT for Windows.
- GETA RAT, ARES RAT, and Desk RAT: Newer cross-platform RATs (Go-based and Python-based) identified in campaigns targeting both Windows and Linux environments, emphasizing system profiling, data exfiltration, and real-time host monitoring.
Beyond RATs, the group employs various other tools and malware:
- ApoloStealer: A new stealer payload identified in ElizaRAT campaigns, designed to collect desktop files and other user information.
- njRAT and DarkComet: Commodity RATs that Transparent Tribe has incorporated into their operations.
- Limepad: An exfiltration tool used in conjunction with credential harvesting campaigns.
- USBWorm: Malware designed to spread across systems by infecting removable media, detected on numerous systems.
- GLOBSHELL and PYSHELLFOX: Python-based information-gathering tools targeting Linux systems, with PYSHELLFOX specifically extracting data from Mozilla Firefox.
- Custom Golang-compiled espionage tools: Described as “all-in-one” tools capable of file exfiltration, screenshot capture, uploads, downloads, and command execution, sometimes modified from open-source projects like Discord-C2.
Current Status
Transparent Tribe remains a highly active and persistent threat actor, with reported campaigns extending into late 2025 and early 2026. The group continuously adapts its tactics, techniques, and procedures (TTPs), demonstrating a commitment to refining its attack methodologies. This includes evolving malware staging techniques, introducing new malware variants with enhanced evasion capabilities, and embracing cross-platform programming languages to expand its reach.
Their targeting has demonstrably broadened beyond traditional government and military entities to include critical infrastructure, the education sector, and, most recently, India’s cybersecurity and OSINT startup ecosystem. This expansion suggests a strategic effort to gather a wider array of intelligence relevant to India’s national security landscape. Transparent Tribe continues to rely heavily on social engineering and the abuse of legitimate cloud services for both malware distribution and command-and-control infrastructure. Their operations are characterized by a focus on long-term intelligence collection and persistent access rather than short-lived disruption or financial gain, making them a significant and enduring cyber espionage threat to India and related regions.
Related content
Gorgon Group (G0078): Hybrid Threat Actor Profile
Adversary ProfileMolerats (G0021): Persistent Cyber Espionage in the Middle East
Adversary ProfileGroup5 (G0043): Persistent Iranian-Linked Espionage Targeting Syrian Opposition
Adversary ProfileAPT-C-36 (Blind Eagle): A Persistent Threat to Latin America
Worried this actor targets your sector?
Let's map your exposure before they find it themselves.
Book an advisory call