On April 22, 2025, a terrorist attack in Baisaran Valley led to 26 civilian deaths and triggered a halt to cross-border trade between India and Pakistan. Following this, cyber-attacks increased against Indian government offices and educational institutes, primarily conducted by APT36 and various hacktivist groups using phishing and malware tools like Crimson RAT. #APT36 #CyberAttack #CrimsonRAT #IndiaPakistan #CyberWarfare
Keypoints
- On April 22, 2025, a terrorist attack in Baisaran Valley resulted in 26 civilian casualties, marking the deadliest such attack in India since 2008.
- This event led to the suspension of cross-border trade between India and Pakistan, worsening bilateral tensions.
- APT36, a Pakistan-linked threat actor, launched targeted phishing campaigns and deployed Crimson RAT malware against Indian government offices.
- Hacktivist groups such as Cyber Group HOAX1337, IOK Hacker, and National Cyber Crew targeted Indian educational institutions and websites following trade restrictions.
- APT36 used malicious PDF files, macro-embedded Excel and PowerPoint files with social engineering lures to compromise victims.
- Crimson RAT collects machine information, constructs command and control (C2) infrastructure, and establishes persistence on infected machines.
- CyberProof’s security measures have successfully protected its customers from these ongoing waves of attacks amid heightened regional tensions.
MITRE Techniques
- [T1566] Phishing – APT36 used phishing URLs embedded in malicious PDFs and macros to deceive users and deliver malware. (“This PDF file serves the phishing URL below if user executes the file”)
- [T1204] User Execution – The campaign relied on victims opening macro-enabled Excel and PowerPoint files to trigger malicious code execution. (“macro embedded PowerPoint file that had malicious macro very similar to the older macro embedded APT36 droppers”)
- [T1059] Command and Scripting Interpreter – Crimson RAT uses scripting to collect system information and construct command & control servers. (“First, it collects user machine information,” “Next, C2 construction using CyberChef is observed”)
- [T1547] Boot or Logon Autostart Execution – Persistence is created by Crimson RAT to maintain long-term access. (“Finally, it creates persistence”)
Indicators of Compromise
- [IP Addresses] Command and control and phishing infrastructure – 37.221.64.134, 84.54.51.12, 45.141.59.72, and many others.
- [File Hashes] Malicious macro-enabled files and malware samples – d946e3e94fec670f9e47aca186ecaabe (malicious PowerPoint file), 6fcbcdcafc5accf1b2b0453eccd93c203ab1dca9920521b107c9cff8ce236eb2, and more hashes.
- [Domains] Phishing and malware hosting domains mimicking Indian government sites – iaf.nic.in.ministryofdefenceindia.org, jkpolice.gov.in.kashmirattack.exposed, nationaldefensecollege[.]com
- [File Names] Malicious lure documents – Report & Update Regarding Pahalgam Terror Attack.ppam, Agenda Points of Meeting of Dept of Defence held at 11March 25.html
- [URLs] Malicious URL samples used for phishing and redirections – email.gov.in.indiandefence.work, email.gov.in.modindia.link