{"id":454,"count":1,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2013<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Pakistan (ISI Suspected)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Military Intelligence<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Crimson RAT, Android malware, honeytrap operations, Indian military and government targeting<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">APT36, ProjectM, MYTHIC LEOPARD, Earth Karkadann<\/div>\n  <\/div>\n<\/div>\n<p>Transparent Tribe, designated APT36, is a Pakistan-based threat actor widely assessed to be affiliated with or operated by Pakistan's Inter-Services Intelligence (ISI), with a primary mandate focused on espionage against Indian military personnel, defence officials, government employees, and entities associated with Indian national security. The group is one of the most active and persistent threats to Indian government and defence sector cybersecurity, maintaining continuous operations for over a decade.<\/p>\n<p>Transparent Tribe is particularly known for \"honeytrap\" operations ,  creating fake social media profiles of attractive women to befriend Indian military and government targets, building relationships over extended periods before convincing targets to install malicious applications or visit credential-harvesting websites. This human intelligence approach, translated into a digital context, demonstrates sophisticated understanding of both social engineering psychology and operational security.<\/p>\n<p>The group's primary malware is Crimson RAT ,  a custom-developed Windows remote access trojan used for persistent surveillance, file exfiltration, keylogging, and screen capture from compromised military and government systems. The group has also developed Android-based mobile spyware distributed through trojanised versions of legitimate applications and fake \"secure communication\" apps promoted to Indian military personnel as official tools.<\/p>\n<p>Transparent Tribe conducts particularly intensive operations during periods of elevated India-Pakistan tensions ,  including increased activity following the 2019 Pulwama attack and subsequent military confrontation ,  demonstrating their role as an active intelligence collection tool in Pakistan's strategic toolkit for monitoring Indian military intentions and capabilities. Their sustained decade-long operational history against Indian targets makes them a persistent priority threat for Indian cybersecurity and intelligence agencies.<\/p>\n\n<p><strong>Threat Mitigation and Strategic Hardening:<\/strong> Network defense against campaigns linked to <strong>Transparent Tribe<\/strong> requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our <a href=\"https:\/\/cyberasia.io\/cyber-risk-checker\/\" style=\"color: #facc15; text-decoration: none;\">Cyber Risk Checker<\/a> and report critical indicators via <a href=\"https:\/\/cyberasia.io\/secure-drop\/\" style=\"color: #facc15; text-decoration: none;\">Secure Drop<\/a>.<\/p>","link":"https:\/\/cyberasia.io\/actor\/transparent-tribe\/","name":"Transparent Tribe","slug":"transparent-tribe","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/454","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}