APT36 Linux .desktop phishing campaign against Indian government and defense entities
Campaign
Summary
Hide ▲
Show ▼
The APT36 campaign is using malicious Linux .desktop files in phishing ZIPs to target government and defense entities in India, creating risk of data exfiltration and persistent espionage access. The operation was first spotted on August 1, 2025 and remains ongoing. The delivery chain abuses the `.desktop` `Exec=` field to fetch and run a payload while hiding execution behind a benign-looking PDF decoy.
Related Happenings
NosyDoor backdoor activity using OneDrive and Google Drive C&C
Malware Activity
H score29
First: 18.12.2025 19:34
Last: 18.12.2025 19:34
Sources 1
About this happening:
The NosyDoor backdoor is being used to exfiltrate files and run shell commands inside compromised networks, making the LongNosedGoblin toolset more dangerous. The...
NosyDoor backdoor activity using OneDrive and Google Drive C&C
Malware ActivityAbout this happening: The NosyDoor backdoor is being used to exfiltrate files and run shell commands inside compromised networks, making the LongNosedGoblin toolset more dangerous. The...
APT42 SpearSpecter espionage campaign
Campaign
H score41
First: 14.11.2025 16:40
Last: 14.11.2025 16:40
Sources 1
About this happening:
The APT42 SpearSpecter campaign is ongoing, and it is targeting senior defense and government officials with personalized social engineering that also reaches fa...
APT42 SpearSpecter espionage campaign
CampaignAbout this happening: The APT42 SpearSpecter campaign is ongoing, and it is targeting senior defense and government officials with personalized social engineering that also reaches fa...
TransparentTribe BOSS Linux phishing espionage campaign
Campaign
H score27
First: 23.10.2025 18:30
Last: 23.10.2025 18:30
Sources 1
About this happening:
A TransparentTribe / APT36 espionage campaign targeting Indian government Linux systems has been uncovered, showing an updated phishing operation built around dedicated...
TransparentTribe BOSS Linux phishing espionage campaign
CampaignAbout this happening: A TransparentTribe / APT36 espionage campaign targeting Indian government Linux systems has been uncovered, showing an updated phishing operation built around dedicated...
TikTok activation-guide ClickFix infostealer campaign
Campaign
H score34
First: 19.10.2025 21:28
Last: 19.10.2025 21:28
Sources 1
About this happening:
A TikTok-based ClickFix campaign is using fake free activation guides to deliver info-stealing malware, putting users seeking software activations at risk of cre...
TikTok activation-guide ClickFix infostealer campaign
CampaignAbout this happening: A TikTok-based ClickFix campaign is using fake free activation guides to deliver info-stealing malware, putting users seeking software activations at risk of cre...
CAPI Backdoor phishing ZIP campaign targeting Russian automobile and e-commerce sectors
Campaign
H score30
First: 18.10.2025 14:41
Last: 18.10.2025 14:41
Sources 1
About this happening:
A new CAPI Backdoor campaign is targeting Russian automobile and e-commerce sectors, using phishing emails with ZIP archives to deliver malware that can steal brow...
CAPI Backdoor phishing ZIP campaign targeting Russian automobile and e-commerce sectors
CampaignAbout this happening: A new CAPI Backdoor campaign is targeting Russian automobile and e-commerce sectors, using phishing emails with ZIP archives to deliver malware that can steal brow...
Timeline
-
22.08.2025 21:35 1 articles · 10mo ago
APT36 phishing ZIP attacks first spotted in India
Exploitation ObservedAPT36 began phishing-delivered ZIP campaigns against government and defense entities in India, disguising a malicious Linux `.desktop` launcher as a PDF and using the launcher to fetch and execute a payload, present a benign decoy PDF, and establish persistence for espionage and data exfiltration. The activity was first spotted on August 1, 2025 and remained ongoing.
Show sources
- APT36 hackers abuse Linux .desktop files to install malware in new attacks — www.bleepingcomputer.com — 22.08.2025 21:35
-
22.08.2025 21:35 1 articles · 10mo ago
CYFIRMA and CloudSEK detail APT36 Linux launcher abuse
Technical Analysis UpdateCYFIRMA and CloudSEK describe APT36's campaign against government and defense entities in India, noting phishing-delivered ZIP archives that hide a malicious Linux `.desktop` launcher, abuse the `Exec=` field to write payloads under `/tmp/`, fetch code from an attacker server or Google Drive, launch a decoy PDF in Firefox, and use `X-GNOME-Autostart-enabled=true`, cron jobs, and systemd services for persistence. The payload is described as a Go-based ELF executable that supports data exfiltration and remote command execution over a bi-directional WebSocket channel.
Show sources
- APT36 hackers abuse Linux .desktop files to install malware in new attacks — www.bleepingcomputer.com — 22.08.2025 21:35