By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities
Computing

APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities

News Room
Last updated: 2026/02/11 at 11:23 AM
News Room Published 11 February 2026
Share
APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities
SHARE

Ravie LakshmananFeb 11, 2026Cyber Espionage / Threat Intelligence

Indian defense sector and government-aligned organizations have been targeted by multiple campaigns that are designed to compromise Windows and Linux environments with remote access trojans capable of stealing sensitive data and ensuring continued access to infected machines.

The campaigns are characterized by the use of malware families like Geta RAT, Ares RAT, and DeskRAT, which are often attributed to Pakistan-aligned threat clusters tracked as SideCopy and APT36 (aka Transparent Tribe). SideCopy, active since at least 2019, is assessed to operate as a subdivision of Transparent Tribe.

“Taken together, these campaigns reinforce a familiar but evolving narrative,” Aditya K. Sood, vice president of Security Engineering and AI Strategy at Aryaka, said. “Transparent Tribe and SideCopy are not reinventing espionage – they are refining it.”

“By expanding cross-platform coverage, leaning into memory-resident techniques, and experimenting with new delivery vectors, this ecosystem continues to operate below the noise floor while maintaining strategic focus.”

Common to all the campaigns is the use of phishing emails containing malicious attachments or embedded download links that lead prospective targets to attacker-controlled infrastructure. These initial access mechanisms serve as a conduit for Windows shortcuts (LNK), ELF binaries, and PowerPoint Add-In files that, when opened, launch a multi-stage process to drop the trojans.

The malware families are designed to provide persistent remote access, enable system reconnaissance, collect data, execute commands, and facilitate long-term post-compromise operations across both Windows and Linux environments.

One of the attack chains is as follows: a malicious LNK file invokes “mshta.exe” to execute an HTML Application (HTA) file hosted on compromised legitimate domains. The HTA payload contains JavaScript to decrypt an embedded DLL payload, which, in turn, processes an embedded data blob to write a decoy PDF to disk, connects to a hard-coded command-and-control (C2) server, and displays the saved decoy file.

After the lure document is displayed, the malware checks for installed security products and adapts its persistence method accordingly prior to deploying Geta RAT on the compromised host. It’s worth noting this attack chain was detailed by CYFIRMA and Seqrite Labs researcher Sathwik Ram Prakki in late December 2025.

Geta RAT supports various commands to collect system information, enumerate running processes, terminate a specified process, list installed apps, gather credentials, retrieve and replace clipboard contents with attacker-supplied data, capture screenshots, perform file operations, run arbitrary shell commands, and harvest data from connected USB devices.

Running parallel to this Windows-focused campaign is a Linux variant that employs a Go binary as a starting point to drop a Python-based Ares RAT by means of a shell script downloaded from an external server. Like Geta RAT, Ares RAT can also run a wide range of commands to harvest sensitive data and run Python scripts or commands issued by the threat actor.

Aryaka said it also observed another campaign where the Golang malware, DeskRAT, is delivered via a rogue PowerPoint Add-In file that runs embedded macro to establish outbound communication with a remote server to fetch the malware. APT36’s use of DeskRAT was documented by Sekoia and QiAnXin XLab in October 2025.

“These campaigns demonstrate a well-resourced, espionage-focused threat actor deliberately targeting Indian defense, government, and strategic sectors through defense-themed lures, impersonated official documents, and regionally trusted infrastructure,” the company said. “The activity extends beyond defense to policy, research, critical infrastructure, and defense-adjacent organizations operating within the same trusted ecosystem.”

“The deployment of Desk RAT, alongside Geta RAT and Ares RAT, underscores an evolving toolkit optimized for stealth, persistence, and long-term access.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article British Transport Police launch facial recognition tech trial – UKTN British Transport Police launch facial recognition tech trial – UKTN
Next Article Tired of AI Hallucinations? Use These 7 Expert Tips to Fix Your Image Errors Fast Tired of AI Hallucinations? Use These 7 Expert Tips to Fix Your Image Errors Fast
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

‘Best of both worlds’: Seattle startup founder community Foundations is expanding to San Francisco
‘Best of both worlds’: Seattle startup founder community Foundations is expanding to San Francisco
Computing
Reanimal review – you will never turn your back on a pelican again as long as you live
Reanimal review – you will never turn your back on a pelican again as long as you live
News
Two xAI cofounders announce departures in quick succession
Two xAI cofounders announce departures in quick succession
News
Mike Sicilia, CEO of Oracle, places data sovereignty and quality at the center of the AI ​​strategy
Mike Sicilia, CEO of Oracle, places data sovereignty and quality at the center of the AI ​​strategy
Mobile

You Might also Like

‘Best of both worlds’: Seattle startup founder community Foundations is expanding to San Francisco
Computing

‘Best of both worlds’: Seattle startup founder community Foundations is expanding to San Francisco

5 Min Read
Engagement rate benchmarks and formulas: 2026 update
Computing

Engagement rate benchmarks and formulas: 2026 update

22 Min Read
Seattle startup Integrate lands M to expand its super-secure project management tool for defense tech
Computing

Seattle startup Integrate lands $17M to expand its super-secure project management tool for defense tech

3 Min Read
AMD ROCm TheRock 7.11 Released, Ubuntu Making Progress On Shipping ROCm Packages
Computing

AMD ROCm TheRock 7.11 Released, Ubuntu Making Progress On Shipping ROCm Packages

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?