Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

MeitY mandates cyber audits to counter AI-related vulnerabilities

June 27, 2026

Boosting Mobile Security: Extending Cyber Resilience with Aurora Mobile Threat Defense

June 26, 2026

Global Government Trap Exposed: 11,000+ Fake Portals Target Citizens Worldwide

June 26, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » APT36 Launches Golang-Based DeskRAT Malware Campaign Against Indian Government
Cybercrime and Ransomware

APT36 Launches Golang-Based DeskRAT Malware Campaign Against Indian Government

Staff WriterBy Staff WriterOctober 24, 2025No Comments4 Mins Read3 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Summary Points

  1. A Pakistan-linked threat actor, Transparent Tribe (APT36), targeted Indian government entities in 2025 using spear-phishing with ZIP files and cloud links to deliver Golang malware called DeskRAT, supporting remote commands and persistent Linux backdoors.
  2. DeskRAT employs multiple persistence methods and remotely manages tasks like file browsing, data exfiltration, and payload execution, with C2 servers using stealthy, non-public domain name servers to evade detection.
  3. The campaign also includes Windows variants of StealthServer with anti-debug, anti-analysis features, and Linux variants with commands for file management and execution, indicating cross-platform malware evolution.
  4. These developments are part of broader regional cyber activity, involving sophisticated threat groups like Bitter APT, SideWinder, OceanLotus, and Mysterious Elephant, targeting governments, critical infrastructure, and exfiltrating sensitive communications including WhatsApp data.

The Issue

In 2025, Pakistan-linked cyber actors, specifically the group known as Transparent Tribe (or APT36), launched a series of targeted spear-phishing attacks against Indian government agencies, aiming to infiltrate their networks using a new form of malware called DeskRAT, written in the Go programming language. These cybercriminals sent deceptive emails with ZIP attachments or links to cloud-hosted archives that, once opened, displayed a false PDF while secretly executing malicious code. This code was designed to target Bharat Operating System Solutions (BOSS) Linux systems, establishing persistent remote access through various methods such as systemd services, cron jobs, or auto-start directories, all orchestrated to exfiltrate data and maintain covert command-and-control channels. The malware’s communication with its command servers was carefully hidden, transitioning from using public platforms like Google Drive to dedicated command servers to evade detection. The report, sourced from cybersecurity firm Sekoia, highlights the group’s sophisticated approach, utilizing multiple command structures and adaptable techniques across both Linux and Windows environments, amid a broader regional pattern of cyber espionage campaigns targeting critical sectors in South and Southeast Asia.

The reporting emphasizes a worrying evolution in the threat landscape, where a highly capable hacking collective is deploying custom malware, exploiting vulnerabilities, and implementing complex persistence mechanisms with high operational tempo. Parallel campaigns from other regional groups—such as Bitter APT, SideWinder, OceanLotus, and Mysterious Elephant—have similarly targeted government agencies, military infrastructure, and private enterprises across China, Pakistan, Myanmar, and neighboring nations, often seeking to steal sensitive communications, credentials, and reconnaissance data like WhatsApp and Chrome cookies. These operations, as detailed by cybersecurity experts, showcase an alarming trend of state-sponsored, cross-platform cyber espionage, underlining the increasing sophistication and geopolitical stakes of cyber threats in the Asian region.

Risks Involved

The cyberattack titled ‘APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign’ underscores a critical vulnerability that could similarly threaten any organization, including your business, by exposing sensitive data and disrupting operations through sophisticated malware often delivered via clandestine tactics. Such attacks leverage advanced tools like Golang-based malware to bypass traditional security measures, enabling cybercriminals to silently infiltrate networks, exfiltrate confidential information, or even disable key systems. If your business becomes a target, the consequences could be severe—ranging from intellectual property theft and financial loss to damaging your reputation and losing customer trust—that can substantially impair future growth and stability. Therefore, understanding the evolving threat landscape and implementing proactive, multi-layered cybersecurity defenses are essential to safeguarding your assets and ensuring operational resilience against such malicious campaigns.

Possible Next Steps

In the rapidly evolving cybersecurity landscape, prompt remediation of threats such as the ‘APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign’ is critical to prevent extensive damage, data breaches, and operational disruptions. Swift action not only curtails the threat actor’s window of opportunity but also reinforces an organization’s resilience against future attacks.

Detection & Analysis

  • Implement continuous monitoring tools to identify unusual activity.
  • Conduct forensic analysis to understand malware characteristics and infiltration vector.
  • Employ threat intelligence to track threat actor tactics, techniques, and procedures (TTPs).

Containment & Eradication

  • Isolate affected systems immediately to prevent lateral movement.
  • Remove malware artifacts and close exploited vulnerabilities.
  • Reset compromised credentials and disable malicious accounts.

Recovery & Restoration

  • Reinstall or restore systems from trusted backups.
  • Patch software and firmware to address vulnerabilities used by the malware.
  • Monitor restored systems for signs of re-infection.

Prevention & Hardening

  • Enforce strict access controls and multi-factor authentication.
  • Update and patch all software regularly to mitigate known exploits.
  • Conduct employee cybersecurity awareness training to recognize spear-phishing attempts.

Policy & Coordination

  • Review and strengthen incident response plans aligned with NIST CSF principles.
  • Collaborate with national cybersecurity agencies for threat intelligence sharing.
  • Conduct regular security audits and penetration testing to identify weak points.

Continue Your Cyber Journey

Discover cutting-edge developments in Emerging Tech and industry Insights.

Understand foundational security frameworks via NIST CSF on Wikipedia.

Disclaimer: The information provided may not always be accurate or up to date. Please do your own research, as the cybersecurity landscape evolves rapidly. Intended for secondary references purposes only.

Cyberattacks-V1cyberattack-v1-multisource

CISO Update computer security cyber attacks cyber news cyber risk cyber security news cyber security news today cyber security updates cyber updates cybercrime Cybersecurity data breach hacker news hacking news how to hack information security MX1 network security ransomware malware risk management software vulnerability the hacker news
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article3,000 YouTube Videos Revealed as Malware Traps in Huge Ghost Network!
Next Article UN Cybercrime Accord Faces Backlash Over Threat to Researchers
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

MeitY mandates cyber audits to counter AI-related vulnerabilities

June 27, 2026

Boosting Mobile Security: Extending Cyber Resilience with Aurora Mobile Threat Defense

June 26, 2026

Global Government Trap Exposed: 11,000+ Fake Portals Target Citizens Worldwide

June 26, 2026

Comments are closed.

Latest Posts

Japan’s Ground Self-Defense Force Faces Malware Threat via Infected USB Drives

June 26, 2026

Zero Trust in OT: A 90-Day Board Engagement & Action Plan

June 26, 2026

Mythos: A Signal, Not a Siren—What Frontier AI Means for CISOs

June 26, 2026

Urgent: Cisco Unified CM Vulnerability Under Exploitation

June 26, 2026
Don't Miss

MeitY mandates cyber audits to counter AI-related vulnerabilities

By Staff WriterJune 27, 2026

Essential Insights AI-powered tools enable highly targeted phishing, deepfakes, and voice clones, increasing deception and…

Boosting Mobile Security: Extending Cyber Resilience with Aurora Mobile Threat Defense

June 26, 2026

Global Government Trap Exposed: 11,000+ Fake Portals Target Citizens Worldwide

June 26, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • MeitY mandates cyber audits to counter AI-related vulnerabilities
  • Boosting Mobile Security: Extending Cyber Resilience with Aurora Mobile Threat Defense
  • Global Government Trap Exposed: 11,000+ Fake Portals Target Citizens Worldwide
  • FBI: Russian Hackers Target Signal Backup Recovery Keys
  • Metasploit Modules Enable Exploits for Audiobookshelf & Others
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

MeitY mandates cyber audits to counter AI-related vulnerabilities

June 27, 2026

Boosting Mobile Security: Extending Cyber Resilience with Aurora Mobile Threat Defense

June 26, 2026

Global Government Trap Exposed: 11,000+ Fake Portals Target Citizens Worldwide

June 26, 2026
Most Popular

Protecting MCP Security: Defeating Prompt Injection & Tool Poisoning

January 30, 202633 Views

Unlock the Power of Free WormGPT: Harnessing DeepSeek, Gemini, and Kimi-K2 AI Models

November 27, 202530 Views

The New Face of DDoS is Impacted by AI

August 4, 202528 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.