Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
APT36 and SideCopy Target Indian Defense with RATs

APT36 and SideCopy Target Indian Defense with RATs

Posted on February 11, 2026 By CWS

Recent cyber espionage campaigns targeting the Indian defense sector have raised alarms due to their sophisticated use of remote access trojans (RATs). These operations, attributed to threat actors like APT36 and SideCopy, aim to infiltrate both Windows and Linux systems to steal sensitive information and maintain prolonged access to compromised devices.

Key Players and Malware Used

The campaigns are primarily associated with malware families such as Geta RAT, Ares RAT, and DeskRAT. These tools are linked to SideCopy and APT36, with the latter also known as Transparent Tribe. Active since 2019, SideCopy is considered an offshoot of Transparent Tribe, indicating a well-coordinated strategy behind these operations.

Aditya K. Sood, Aryaka’s vice president of Security Engineering and AI Strategy, highlights that these campaigns refine rather than reinvent traditional espionage techniques. By expanding their reach across platforms and exploring new delivery methods, these threat actors continue to operate below the radar while maintaining their strategic focus.

Infiltration Techniques

The attack strategies often begin with phishing emails that contain malicious attachments or download links, leading victims to attacker-controlled servers. These initial vectors use Windows shortcuts, ELF binaries, and PowerPoint Add-Ins to initiate a multi-stage process to deploy RATs.

Once deployed, these RATs provide persistent access, allowing attackers to conduct system reconnaissance, execute commands, and facilitate long-term operations on both Windows and Linux platforms. One particular attack chain involves a malicious LNK file that executes an HTML Application, eventually leading to the installation of Geta RAT after bypassing security checks.

Ongoing Threats and Response

Parallel to the Windows attacks, a Linux variant employs a Go binary to install a Python-based Ares RAT via a shell script. Similar to Geta RAT, Ares RAT enables a wide array of commands to exfiltrate data and execute attacker-driven scripts.

In another observed campaign, the Golang malware DeskRAT is distributed through a rogue PowerPoint Add-In. This tactic underscores the evolving arsenal of tools optimized for stealth and persistence. Documented by Sekoia and QiAnXin XLab, APT36’s use of DeskRAT highlights their ongoing efforts to target strategic Indian sectors.

These campaigns demonstrate a deliberate approach by well-resourced threat actors to compromise Indian defense and other critical sectors. By using defense-themed lures and impersonated official documents, they exploit trusted regional infrastructure to expand their reach beyond defense to policy, research, and critical infrastructure organizations.

As these threats evolve, it is crucial for targeted entities to bolster their cybersecurity defenses and remain vigilant against such sophisticated espionage tactics.

The Hacker News Tags:APT36, ARES RAT, cyber espionage, Cybersecurity, DeskRAT, GETA RAT, Indian defense, Linux, remote access trojan, SideCopy, Windows

Post navigation

Previous Post: Prometei Botnet Targets Windows Servers with Advanced Tactics
Next Post: Signs of Concealed Information in Security Management

Related Posts

OpenAI Unveils GPT-5.4-Cyber for Enhanced Cybersecurity OpenAI Unveils GPT-5.4-Cyber for Enhanced Cybersecurity The Hacker News
3 SOC Challenges You Need to Solve Before 2026 3 SOC Challenges You Need to Solve Before 2026 The Hacker News
New RowHammer Attack Variant Degrades AI Models on NVIDIA GPUs New RowHammer Attack Variant Degrades AI Models on NVIDIA GPUs The Hacker News
CL0P-Linked Hackers Breach Dozens of Organizations Through Oracle Software Flaw CL0P-Linked Hackers Breach Dozens of Organizations Through Oracle Software Flaw The Hacker News
Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch The Hacker News
Sophos and SonicWall Patch Critical RCE Flaws Affecting Firewalls and SMA 100 Devices Sophos and SonicWall Patch Critical RCE Flaws Affecting Firewalls and SMA 100 Devices The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft
  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft
  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark