Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Transparent Tribe, APT 36, ProjectM, Mythic Leopard, TEMP.Lapis, Copper Fieldstone, Earth Karkaddan, STEPPY-KAVACH, Green Havildar, APT-C-56, Storm-0156, Opaque Draco, G0134, C-Major, APT36, TMP.Lapis, COPPER FIELDSTONE
Proofpoint researchers recently uncovered evidence of an advanced persistent threat (APT) against Indian diplomatic and military resources. Our investigation began with malicious emails sent to Indian embassies in Saudi Arabia and Kazakstan but turned up connections to watering hole sites focused on Indian military personnel and designed to drop a remote access Trojan (RAT) with a variety of data exfiltration functions. Our analysis shows that many of the campaigns and attacks appear related by common IOCs, vectors, payloads, and language, but the exact nature and attribution associated with this APT remain under investigation. At this time, the background and analysis in this paper provide useful forensics and detail our current thinking on the malware that we have dubbed “MSIL/Crimson”. Transparent Tribe may be related to Gorgon Group and SideCopy . Their malicious infrastructure was infiltrated by Turla, Waterbug, Venomous Bear in 2022. Transparant Tribe has been observed to use the Andromeda botnet (operated by Andromeda Spider ).
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database