Home/Threat Actor/Transparent Tribe
Threat Actor

Transparent Tribe

mythic_leopard · pakistan · active since 2013

Transparent Tribe (APT36 / Mythic Leopard / Earth Karkaddan / C-Major / G0134) is a Pakistan-aligned cyber-espionage cluster active since 2013, widely assessed by vendor research and Indian CERT-In to operate in alignment with Pakistan's Inter-Services Intelligence (ISI), responsible for sustained Crimson-RAT and CapraRAT operations against Indian Army, Navy, Air Force, paramilitary, diplomatic, DRDO, and BOSS-Linux government targets since 2016, defined by its toolkit durability, social-engineering depth (honeytrap profiles, fake Kavach MFA installers), and patient regional collection rather than by novel exploitation or cutting-edge tradecraft.

pakistan confidence: high 21 aliases MITRE ATT&CK G0134 ↗

Profile

Transparent Tribe (also tracked as APT36, Mythic Leopard, Earth Karkaddan, C-Major, ProjectM, Copper Fieldstone, TMP.Lapis, and MITRE ATT&CK G0134) is a Pakistan-aligned cyber-espionage cluster active since at least 2013. The cluster is widely assessed by vendor research and by Indian CERT-In to operate in alignment with Pakistan's Inter-Services Intelligence (ISI) or affiliated Pakistan military intelligence elements. No formal government attribution has been issued, India has not publicly named ISI by name, and no US, UK, or EU government has issued a formal attribution, so this record carries the "Pakistan-aligned" framing as suspected rather than confirmed. Operationally APT36 is defined by patient, sustained, regionally- focused collection against Indian government, military, paramilitary, and diplomatic targets, not by novel exploit development or cutting-edge tradecraft. The cluster's signature is its toolkit durability and its social-engineering depth. Crimson RAT, a .NET- based Windows implant, has been the central first-stage and second-stage implant since 2016 with continuous incremental development across many years. ObliqueRAT (a successor or sibling Windows implant) and Peppy RAT have supplemented Crimson RAT in various campaigns. On Android, a central platform for APT36 because Indian military and paramilitary personnel routinely carry Android devices on duty, the cluster operates CapraRAT (derived from the open-source AndroRAT framework), StealthSpy / StealthAgent, and Crimson Mobile RAT variants, distributed via honeytrap social-engineering profiles (fake matrimonial, dating, and Facebook identities) and via fake versions of legitimate Indian government and consumer apps. A 2023 expansion to Linux added the Poseidon backdoor targeting Indian government BOSS Linux (Bharat Operating System Solutions) desktops, with follow-on GLOBSHELL and SILENT-VENOM cross-platform tooling disclosed in 2024. A defining lure family is fake-installer phishing impersonating Kavach, the Indian government's mandatory multi-factor authentication application for officials accessing NIC email and government services. Because Kavach is mandatory across Indian government, the Kavach lure family achieves very wide coverage against Indian officials, and SEQRITE, Talos, K7, and Cyfirma have all documented sustained Kavach-themed campaigns through 2022-2024. Initial access is overwhelmingly via spear-phishing with maldoc or fake-installer attachments, weaponized DOCX, ODT, PDF, and Windows-installer files. Where exploitation is used at all, it is typically against long-lived Office vulnerabilities (CVE-2017- 11882, CVE-2017-8570, CVE-2017-0199, CVE-2018-0802) rather than against recent n-day or zero-day vulnerabilities. The cluster does not operate at the technical sophistication tier of the major Russian or Chinese clusters and does not engage in supply- chain or hypervisor-level operations.

its strength is operational tempo, target intimacy, and patient long-dwell collection. A handful of operational pitfalls deserve attention in any reporting that touches APT36: First, "SideCopy", a related cluster historically tracked under Transparent Tribe overlap by some vendors, is now widely treated as a distinct (though related) Pakistan-aligned cluster.

SEQRITE and others have published "Operation SideCopy" reporting that partially overlapped with APT36 but used different first-stage tooling (HTA-based droppers, ReverseRAT, ActionRAT). Treat SideCopy as adjacent but separate. Second, Sikh-and Kashmiri-community targeting in the Indian diaspora abroad (UK, Canada, Australia) by APT36 has at times been confused with separate India-aligned surveillance activity against the same communities. The toolkit and tradecraft are distinctively APT36 (Pakistan-aligned), but the victim category overlap with India-aligned surveillance can confuse reporting. Third, attribution to the ISI specifically, though dominant in vendor reporting, has not been confirmed by formal state attribution and should be presented as suspected.

Aliases

21
transparent tribetransparent_tribemythic leopardmythic_leopardapt36apt-36apt 36earth karkaddanearth_karkaddanc-majorc_majorcmajorprojectmproject_mcopper fieldstonecopper_fieldstoneoperation transparent tribetmp.lapistmp_lapisatk 9g0134

Notable Campaigns

8
2024-2025Continued Operations Against Indian Government and Military (2024-2025)
2024GLOBSHELL / SILENT-VENOM Cross-Platform Expansion (2024)
2023-2025Indian Diaspora and Diplomatic-Mission Targeting (2023-2025)
2023Poseidon Linux Backdoor, BOSS Linux Targeting (2023)
2022-2024Kavach MFA Phishing and Fake Installer Operations (2022-2024)
2018-2022CapraRAT Android Implant Operations (2018 onward, Trend Micro Earth Karkaddan 2022)
2016-2020Crimson RAT Evolution and Operational Tempo (2016-2020)
2016Operation Transparent Tribe (Proofpoint, February 2016)

Attribution & Reporting

Attributed by
Indian CERT-InQuick Heal / SEQRITECisco TalosTrend MicroESETProofpointKasperskySymantecCyfirmaVolexityMicrosoftBlackBerryK7 ComputingAT&T Alien LabsSentinelOneRecorded Future Insikt GroupCluster25CybleZscaler ThreatLabzCYFIRMA
Key reporting
reportProofpoint: Operation Transparent Tribe (February 2016)
reportCisco Talos: Transparent Tribe, Four Years Later (March 2020)
reportCisco Talos: Transparent Tribe Targets Indian Army and Educational Institutions (March 2022)
reportCisco Talos: Transparent Tribe Targets Indian Government Officials with Updated Tools (May 2023)
reportESET: Transparent Tribe, Windows and Android Targets (August 2020)
reportKaspersky GReAT: Transparent Tribe, Part 1 (Crimson RAT August 2020)
reportKaspersky GReAT: Transparent Tribe, Part 2 (Android, October 2020)
reportTrend Micro: Investigating APT36 / Earth Karkaddan's Attack Chain and Malware Arsenal (February 2022)
reportTrend Micro: Earth Karkaddan APT, Adapts with New Toolset (April 2022)
reportSentinelOne Labs: CapraRAT Mimics YouTube to Hijack Android Devices (September 2023)
reportVolexity: APT36 / Transparent Tribe Targets Indian Government Targets with Updated Tooling (June 2023)
reportQuick Heal / SEQRITE: Operation Honeytrap, APT36 Targets Defense Organizations in India (multiple years)
reportSEQRITE: Transparent Tribe APT Actively Lures Indian Army Amidst Increased Targeting of Educational Institutions (2022)
reportBlackBerry: .NET Stub Attributed to Mythic Leopard (February 2023)
reportCyfirma: APT36 Strikes, Targeting Indian Government and Defense (2023)
reportGoogle TAG / Mandiant: Transparent Tribe Supply Chain Attack (2024)
reportRecorded Future Insikt Group: Transparent Tribe Targeting Indian MoD and MeitY (multiple years)
reportCluster25: APT36 Operational Profile (2023-2024)
reportZscaler ThreatLabz: APT36 Poseidon Linux Backdoor Analysis (2023)
reportMalpedia Actor Profile: Transparent Tribe
reportMITRE ATT&CK Group G0134, Transparent Tribe

Operational

State sponsor

Suspected Pakistan state-aligned advanced persistent threat group, widely assessed by vendor research to operate in alignment with, and likely under the direction of, Pakistan's Inter-Services Intelligence (ISI) or affiliated Pakistan military intelligence elements. Indian CERT-In, Quick Heal / SEQRITE (an Indian vendor with deep visibility into India-targeted threats), Trend Micro, Cisco Talos, ESET, Cyfirma, Volexity, and Proofpoint have consistently characterized the cluster's victimology, operational hours, and targeting cadence as consistent with Pakistan state sponsorship. No US, UK, or EU government has issued a formal attribution.

India has not made a formal public attribution to Pakistan ISI by name. The "Pakistan-aligned" framing in this record reflects the dominant vendor and CERT-In assessment but should be treated as suspected rather than formally attributed.

Motivations
espionage, intelligence_gathering, military_intelligence, dissident_surveillance, geopolitical_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)53/60 · 88%
Analytics (MITRE CAR)24/60 · 40%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MESH AGENT ABUSEMSHTASILENT-VENOMSILENT VENOMSTEALTHAGENTSTEALTHSPY
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin