APT36 and Hacktivists Targeting India

APT36 and Hacktivists Targeting India

On April 22, 2025, a terrorist attack in Baisaran Valley led to 26 civilian deaths and triggered a halt to cross-border trade between India and Pakistan. Following this, cyber-attacks increased against Indian government offices and educational institutes, primarily conducted by APT36 and various hacktivist groups using phishing and malware tools like Crimson RAT. #APT36 #CyberAttack #CrimsonRAT #IndiaPakistan #CyberWarfare

Keypoints

  • On April 22, 2025, a terrorist attack in Baisaran Valley resulted in 26 civilian casualties, marking the deadliest such attack in India since 2008.
  • This event led to the suspension of cross-border trade between India and Pakistan, worsening bilateral tensions.
  • APT36, a Pakistan-linked threat actor, launched targeted phishing campaigns and deployed Crimson RAT malware against Indian government offices.
  • Hacktivist groups such as Cyber Group HOAX1337, IOK Hacker, and National Cyber Crew targeted Indian educational institutions and websites following trade restrictions.
  • APT36 used malicious PDF files, macro-embedded Excel and PowerPoint files with social engineering lures to compromise victims.
  • Crimson RAT collects machine information, constructs command and control (C2) infrastructure, and establishes persistence on infected machines.
  • CyberProof’s security measures have successfully protected its customers from these ongoing waves of attacks amid heightened regional tensions.

MITRE Techniques

  • [T1566] Phishing – APT36 used phishing URLs embedded in malicious PDFs and macros to deceive users and deliver malware. (“This PDF file serves the phishing URL below if user executes the file”)
  • [T1204] User Execution – The campaign relied on victims opening macro-enabled Excel and PowerPoint files to trigger malicious code execution. (“macro embedded PowerPoint file that had malicious macro very similar to the older macro embedded APT36 droppers”)
  • [T1059] Command and Scripting Interpreter – Crimson RAT uses scripting to collect system information and construct command & control servers. (“First, it collects user machine information,” “Next, C2 construction using CyberChef is observed”)
  • [T1547] Boot or Logon Autostart Execution – Persistence is created by Crimson RAT to maintain long-term access. (“Finally, it creates persistence”)

Indicators of Compromise

  • [IP Addresses] Command and control and phishing infrastructure – 37.221.64.134, 84.54.51.12, 45.141.59.72, and many others.
  • [File Hashes] Malicious macro-enabled files and malware samples – d946e3e94fec670f9e47aca186ecaabe (malicious PowerPoint file), 6fcbcdcafc5accf1b2b0453eccd93c203ab1dca9920521b107c9cff8ce236eb2, and more hashes.
  • [Domains] Phishing and malware hosting domains mimicking Indian government sites – iaf.nic.in.ministryofdefenceindia.org, jkpolice.gov.in.kashmirattack.exposed, nationaldefensecollege[.]com
  • [File Names] Malicious lure documents – Report & Update Regarding Pahalgam Terror Attack.ppam, Agenda Points of Meeting of Dept of Defence held at 11March 25.html
  • [URLs] Malicious URL samples used for phishing and redirections – email.gov.in.indiandefence.work, email.gov.in.modindia.link


Read more: https://www.cyberproof.com/blog/cyber-attacks-rise-as-tension-mounts-across-india-pakistan-border-post-terrorist-attack/