Thursday, September 10, 2026

APT36 Targets Linux Systems With New Tools Designed to Disrupt Services

Critical infrastructure worldwide faces mounting threats from sophisticated, state-sponsored “espionage ecosystems.”

These well-funded organizations deploy various tools designed to disrupt essential services and gather intelligence.

Some launch denial-of-service (DDoS) attacks against transport hubs and supply chains. In contrast, others seek geopolitical advantage by mining sensitive information and bypassing traditional security measures.

For over a decade, the Indian government and defense organizations have operated under constant digital surveillance.

The espionage ecosystem notably Transparent Tribe (APT36) and the aligned SideCopy cluster has continuously probed and adapted its methods.

Their primary objective remains unchanged: long-term intelligence collection through stealthy, resilient access.

Recent Campaign Activity

Over the past month, Aryaka Threat Research Labs observed multiple active campaigns targeting Indian defense and government organizations across Windows and Linux environments.

Windows Campaign: Attackers used phishing emails delivering LNK and HTA files that deployed GETA RAT, a .NET-based remote access trojan.

The infection chain abuses legitimate Windows components like mshta.exe and XAML deserialization to evade file-based detection.

Layered startup mechanisms ensure continued access even if disruption occurs, creating a durable foothold for extended reconnaissance.

Linux Campaign: A separate operation focused on Linux systems using a Go-based downloader to install ARES RAT, a Python-based remote access tool.

Once deployed, ARES RAT performs automated system profiling, recursive file enumeration, and structured data exfiltration.

Persistence is achieved through systemd user services, allowing the malware to survive reboots while blending into normal operations. This signals intent to maintain equal capability across platforms.

Emerging Threat: Desk RAT

Researchers also observed campaigns delivering Desk RAT, a Go-based remote access trojan distributed via malicious PowerPoint Add-In (PPAM) files. Desk RAT emphasizes host telemetry and real-time monitoring, collecting detailed system diagnostics and communicating via WebSocket-based command-and-control.

This design enables continuous surveillance on compromised hosts, reinforcing APT36’s long-term intelligence objectives.

These campaigns reveal how Transparent Tribe and SideCopy refine their espionage tactics.

By expanding cross-platform coverage, using memory-resident techniques, and experimenting with new delivery vectors, this ecosystem operates below detection thresholds while maintaining strategic focus.

For defenders, these are coordinated efforts within a mature threat ecosystem, not isolated incidents.

Detecting and disrupting such actors requires visibility across platforms, attention to behavioral signals, and understanding that persistence not speed is the attacker’s greatest weapon.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News