CYFIRMA Research

CYFIRMA Research- APT36: Multi-Stage LNK Malware Campaign Targeting Indian Government Entities

CYFIRMA

APT36 Targets Indian Entities Using Weaponized Windows Shortcut Files

CYFIRMA has identified a coordinated cyber-espionage campaign attributed to APT36 (Transparent Tribe), a Pakistan-aligned threat actor persistently targeting Indian government entities and strategic sectors.

This campaign highlights APT36’s evolving tradecraft, leveraging malicious Windows shortcut (.LNK) files and multi-stage payload delivery to stealthily compromise victim systems while masquerading as legitimate documents.

This activity underscores APT36’s increasing technical maturity and continued emphasis on espionage-driven operations against Indian interests.

Link to the Research Report: https://www.cyfirma.com/research/apt36-multi-stage-lnk-malware-campaign-targeting-indian-government-entities/

#CyberSecurity #ThreatIntel #APT36 #TransparentTribe #MalwareAnalysis  #IndianGovernment #LNKMalware #CyberEspionage #ThreatResearch  #CYFIRMA #CYFIRMAresearch #ExternalThreatLandscapeManagement #ETLM

https://www.cyfirma.com/