DiscoverCYFIRMA ResearchCYFIRMA Research- APT36 Python Based ELF Malware Targeting Indian Government Entities
CYFIRMA Research- APT36 Python Based ELF Malware Targeting Indian Government Entities

CYFIRMA Research- APT36 Python Based ELF Malware Targeting Indian Government Entities

Update: 2025-12-11
Share

Description

APT36 Targets Indian Government Entities with a New Python-Based ELF Malware.

CYFIRMA has uncovered a new cyber-espionage campaign by APT36 (Transparent Tribe), a Pakistan-based threat actor long known for targeting Indian government entities and strategic sectors.

This campaign showcases a major leap in the group’s technical sophistication — delivering custom Python-based ELF malware through weaponized .desktop shortcut files distributed via spear-phishing.

📌 Key Highlights:
The campaign begins with a malicious ZIP file containing a deceptive .desktop shortcut.
Once executed, the shortcut downloads:
A decoy PDF to distract the user
A malicious ELF payload (swcbc)
A persistence-enabling shell script (swcbc.sh)


The malware establishes C2 communication, executes shell/Python commands, steals files, takes screenshots, and maintains persistence.

Infrastructure used includes Lionsdenim[.]xyz and 185.235.137.90, both tied to APT36’s ongoing espionage operations.

The ELF implant is a PyInstaller-packed RAT, supporting cross-platform execution on both Linux and Windows.

Link to the Research Report: APT36 Python Based ELF Malware Targeting Indian Government Entities - CYFIRMA

#CyberSecurity #ThreatIntel #APT36 #MalwareAnalysis #IndianGovernment   #LinuxMalware #CYFIRMA #CyberEspionage #ThreatResearch #ELFMalware   #PyInstaller #TransparentTribe #ExternalThreatLandscapeManagement

https://www.cyfirma.com/

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

CYFIRMA Research- APT36 Python Based ELF Malware Targeting Indian Government Entities

CYFIRMA Research- APT36 Python Based ELF Malware Targeting Indian Government Entities

CYFIRMA