Transparent Tribe

MITRE ATT&CK: G0134 View on attack.mitre.org

Aliases: COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM, C-Major, Transparent Tribe, APT 36, TMP.Lapis, Green Havildar, Earth Karkaddan, Storm-0156, MYTHIC LEOPARD, SideCopy

First seen
2013-01-01 00:00:00
Origin
PK
Primary motivation
espionage
Sophistication
intermediate
Resource level
government
Actor type
nation-state
Related IoCs
100 (74 malicious)
Last IoC activity
2026-09-02 00:39:22
Profile updated
2026-07-07 11:51:15

Targeted industries: defense-and-aerospace government-and-public-sector education-and-nonprofits

Targeted regions: country_code:in country_code:af

Context

Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.

Recent IoC activity

74 malicious indicators in Maltiverse are attributed to Transparent Tribe (G0134). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname ssynergy.in 2026-09-03 2
hostname email-govin.duia.eu 2026-09-03 2
hostname inapharma.in 2026-09-03 1
hostname avadhnama.com 2026-09-03 1
hostname bhai1.ddns.net 2026-09-02 1
hostname cangpeitaoke.oss-cn-hangzhou.aliyuncs.com 2026-09-02 2
hostname cs1.in 2026-09-02 1
hostname clawsindia.in 2026-09-02 1
hostname tprlink.com 2026-09-02 1
hostname coronavirusupdate.ddns.net 2026-09-02 1
hostname kavachauthentication.blogspot.com 2026-09-02 1
hostname ordering-checks.com 2026-09-02 1
hostname intribune.blogspot.com 2026-09-02 1
hostname rockwellroyalhomes.com 2026-09-02 2
hostname whm.maidmart.in 2026-09-01 1
hostname sahirlodhi.com 2026-08-22 1
hostname dns1.indianblog.xyz 2026-08-16 1
hostname gcloudsvc.com 2026-08-16 2
hostname digitalfilestores.com 2026-08-15 1
hostname baseuploads.com 2026-07-30 1

Detection coverage

  • 9 YARA rules
  • 120 Sigma rules

Malware & tools used

  • Drive-by Compromise (attack-pattern)
  • Drive-by Target (attack-pattern)
  • Malicious File (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Dynamic Resolution (attack-pattern)
  • Domains (attack-pattern)
  • Visual Basic (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Domains (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Malicious Link (attack-pattern)
  • Crimson (malware)
  • DarkComet (malware)
  • ObliqueRAT (malware)
  • Peppy (malware)
  • njRAT (malware)

Reports & references

  • Trend Micro — Indian Military Personnel Targeted By Information Theft Campaign Cmajor (report)
  • proofpoint.com — Proofpoint Operation Transparent Tribe Threat Insight En (report)
  • amnesty.org — En (report)
  • CrowdStrike — Adversary Of The Month For May (report)
  • Palo Alto Unit 42 — Unit42 Projectm Link Found Between Pakistani Actor And Operation Transparent Tribe (report)
  • mkd-cirt.mk — 20181009 3 1 M Trends2018 May 2018 Compressed (report)
  • nciipc.gov.in — Nciipc Newsletter July18 (report)
  • cysinfo.com — Cyber Attack Targeting Cbi And Possibly Indian Army Officials (report)
  • s.tencent.com — 669 (report)
  • Mandiant — Apt Group Sends Spea (report)
  • secureworks.com — Copper Fieldstone (report)
  • Trend Micro — Investigating Apt36 Or Earth Karkaddans Attack Chain And Malware (report)
  • sentinelone.com — Capratube Transparent Tribes Caprarat Mimics Youtube To Hijack Android Phones (report)
  • Microsoft — Frequent Freeloader Part I Secret Blizzard Compromising Storm 0156 Infrastructure For Espionage (report)
  • reco.ai — How Apt36 Elizarat Redefines Cyber Espionage (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • CrowdStrike — Mythic Leopard (report)
  • MITRE ATT&CK — G0134 (report)
  • Cisco Talos — Transparent Tribe Infra And Targeting (report)
  • Kaspersky — 98127 (report)

Attributed from

  • C0011 (campaign)

External references