IcePeony and Transparent Tribe Aim at Indian Entities via Cloud-Based Tools

Nov 08, 2024Ravie LakshmananCyber Espionage / Threat Intelligence

In India, prominent organizations have fallen prey to orchestrated malevolent activities by IcePeony, a China-linked cyber group, and the Pakistan-based Transparent Tribe threat gr

IcePeony and Transparent Tribe Target Indian Entities with Cloud-Based Tools

Nov 08, 2024Ravie LakshmananCyber Espionage / Threat Intelligence

IcePeony and Transparent Tribe Target Indian Entities with Cloud-Based Tools

In India, prominent organizations have fallen prey to orchestrated malevolent activities by IcePeony, a China-linked cyber group, and the Pakistan-based Transparent Tribe threat group.

Transparent Tribe’s breaches involve the utilization of ElizaRAT malware and a newly introduced ApoloStealer payload on specific targets, as per Check Point’s recent technical write-up.

“ElizaRAT instances reveal a methodical misuse of cloud-centric platforms like Telegram, Google Drive, and Slack for managing command-and-control communications,” indicated the Israeli firm in its statement.

Initially spotted in July 2023 attacking Indian administrative domains, Transparent Tribe began using ElizaRAT, a Windows remote access tool (RAT). This adversary, known by various aliases such as APT36, Datebug, Earth Karkaddan, Mythic Leopard, Operation C-Major, and PROJECTM, has been active since at least 2013.

Cybersecurity

The array of malware tools at their disposal includes mechanisms to infiltrate Windows, Android, and Linux systems. The increased emphasis on targeting Linux devices stems from the Indian government’s adoption of a custom Ubuntu variant named Maya OS starting last year.

Infection chains are set in motion by Control Panel (CPL) files possibly disseminated via targeted phishi

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.