{"id":29861,"date":"2024-07-24T03:36:02","date_gmt":"2024-07-24T03:36:02","guid":{"rendered":"https:\/\/nsfocusglobal.com\/?p=29861"},"modified":"2026-04-17T18:07:37","modified_gmt":"2026-04-17T18:07:37","slug":"transparenttribes-spear-phishing-targeting-indian-government-departments","status":"publish","type":"post","link":"https:\/\/nsfocusglobal.com\/pt-br\/transparenttribes-spear-phishing-targeting-indian-government-departments\/","title":{"rendered":"TransparentTribe&#8217;s Spear-Phishing Targeting Indian Government Departments"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><p><\/p>\n\n\n\n\n\n<h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p>Leveraging our global threat hunting system,<a href=\"https:\/\/nsfocusglobal.com\/pt-br\/nsfocus-security-labs\/\" target=\"_blank\" rel=\"noreferrer noopener\"> NSFOCUS Security Research Labs<\/a> discovered spear-phishing email attacks by the APT group TransparentTribe targeting Indian government departments on February 2, 2024. The timing of these attacks coincides with the presidential election in India, scheduled for April-May of this year, and the bait documents are related to the &#8220;President&#8217;s Award,&#8221; suggesting a possible connection with the election.<\/p>\n\n\n\n<p>In this incident, the TransparentTribe group utilized a phishing document named &#8220;Recommendation for the award of President&#8217;s.docm.&#8221; The malicious file was concealed within this document and, upon execution, would run the embedded VBA script to extract and execute the malicious program within the file. The ultimate payload used in this attack was the CrimsonRAT remote control program, a common Trojan used by the TransparentTribe attack group. This RAT is capable of collecting system information, downloading and running files, and stealing sensitive information, posing a significant threat.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Introduction of TransparentTribe<\/h2>\n\n\n\n<p>TransparentTribe, also known as ProjectM or APT 36, is an APT attack group originating from Pakistan. It primarily targets India, Kazakhstan, and Afghanistan. The group&#8217;s main objectives are defense, military, embassies, and governments. Their activities date back to as early as 2012. Recently, they have been using phishing emails to deliver malicious docm and xlam documents, utilizing VBA scripts in the documents to release malicious programs, with the aim of stealing user information.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Bait Information<\/h2>\n\n\n\n<p>In this incident, the bait document used by TransparentTribe was named &#8220;Recommendation for the award of President&#8217;s.docm.&#8221; The document&#8217;s content pertains to a document sent by the &#8220;Government of India Ministry of Home Affairs, Police-I Division&#8221; to various Indian government departments. The document impersonates an official document issued by the Indian government on October 17, 2023, mainly discussing recommendations for the award of the President&#8217;s Distinguished Service Medal and the Meritorious Service Medal on Republic Day 2024. This confirms that the target of this attack is Indian government departments.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-1-1.png\"><img fetchpriority=\"high\" decoding=\"async\" width=\"448\" height=\"631\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-1-1.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29862\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-1-1.png 448w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-1-1-213x300.png 213w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-1-1-200x282.png 200w\" sizes=\"(max-width: 448px) 100vw, 448px\" \/><\/a><figcaption class=\"wp-element-caption\">Figure 1: &nbsp;The bait document executed after the phishing email<\/figcaption><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<p>In November 2023, a historical phishing email appeared, also using a bait document containing malicious VBA scripts. The document was named &#8220;Monthly Report MAP.xlam.&#8221; Upon execution, it prompts to enable macros, and if the user clicks to enable, the VBA script will execute, leading to subsequent malicious operations; it also pops up a normal Excel file to cover up the malicious operations.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-2-1.png\"><img decoding=\"async\" width=\"1024\" height=\"152\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-2-1-1024x152.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29864\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-2-1-1024x152.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-2-1-300x45.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-2-1-768x114.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-2-1-600x89.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-2-1-200x30.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-2-1.png 1240w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption class=\"wp-element-caption\">Figure 2: &nbsp;The bait document executed after the phishing email (1)<\/figcaption><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-3.png\"><img decoding=\"async\" width=\"1020\" height=\"321\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-3.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29866\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-3.png 1020w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-3-300x94.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-3-768x242.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-3-600x189.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-3-200x63.png 200w\" sizes=\"(max-width: 1020px) 100vw, 1020px\" \/><\/a><figcaption class=\"wp-element-caption\">Figure 3: &nbsp;The bait document executed after the phishing email (2)<\/figcaption><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-4-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1016\" height=\"248\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-4-1.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29883\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-4-1.png 1016w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-4-1-300x73.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-4-1-768x187.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-4-1-600x146.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-4-1-200x49.png 200w\" sizes=\"(max-width: 1016px) 100vw, 1016px\" \/><\/a><figcaption class=\"wp-element-caption\">Figure 4: &nbsp;The bait document executed after the phishing email (3)<\/figcaption><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<p>It can be seen that this APT group has recently favored impersonating official documents issued by government departments when constructing bait content, using highly targeted content such as government documents and forms. This narrows the scope of the attack, targeting specific targets.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Technical Analysis<\/h2>\n\n\n\n<p>Different from the group&#8217;s previous method of using a downloader to execute remote links to obtain subsequent programs, we have observed that the group&#8217;s recent activities prefer to hide the ultimate payload within the bait document.<\/p>\n\n\n\n<p>The phishing file in this instance is named &#8220;Recommendation for the award of President&#8217;s.docm.&#8221;<\/p>\n\n\n\n<p>The attack process executed after opening this phishing file is as follows:<\/p>\n\n\n\n<p>1. Execute the malicious VBA script;<\/p>\n\n\n\n<p>2. The script will decompress the current file and store the file in the download directory;<\/p>\n\n\n\n<p>3. The script decompresses the document, extracting the word\\media\\image1.png file;<\/p>\n\n\n\n<p>4. The script changes the extension of image1.png to .zip, decompresses it, and extracts the image1.exe file;<\/p>\n\n\n\n<p>5. The script renames image1.exe to itmvroidovs.scr and runs it, which is the ultimate payload CrimsonRAT;<\/p>\n\n\n\n<p>6. The script changes the extension of word\\media\\image2.png to .docx and runs it, using it as a decoy to confuse the attacked user.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/image9.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"438\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/image9-1024x438.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29870\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/image9-1024x438.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/image9-300x128.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/image9-768x328.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/image9-600x257.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/image9-200x86.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/image9.png 1382w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption class=\"wp-element-caption\">&nbsp;Figure 5: &nbsp;The &#8220;Recommendation for the award of President&#8217;s.docm&#8221; file executing the malicious VBA script<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">CrimsonRAT Analysis<\/h2>\n\n\n\n<p>CrimsonRAT is the main Trojan program used by TransparentTribe, with primary functions such as obtaining system information, capturing screenshots, collecting victim host processes, and driver information. It also supports downloading, running files, and stealing sensitive information.<\/p>\n\n\n\n<p>Combining the bait creation time with the official report release time, the timestamp is likely to be genuine, indicating that this incident is a recent attack launched by TransparentTribe.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-6-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"345\" height=\"498\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-6-1.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29908\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-6-1.png 345w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-6-1-208x300.png 208w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-6-1-200x289.png 200w\" sizes=\"(max-width: 345px) 100vw, 345px\" \/><\/a><figcaption class=\"wp-element-caption\">&nbsp;Figure 6: &nbsp;The author and creation time of the bait document<\/figcaption><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-7-1.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-7-1.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29890\" width=\"880\" height=\"182\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-7-1.png 687w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-7-1-300x62.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-7-1-600x124.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-7-1-200x41.png 200w\" sizes=\"(max-width: 880px) 100vw, 880px\" \/><\/a><figcaption class=\"wp-element-caption\">Figure 7: &nbsp;The timestamp of the final payload Trojan<\/figcaption><\/figure>\n<\/div>\n\n\n<p>&nbsp;<\/p>\n\n\n\n<p>In this attack incident, the CrimsonRAT Trojan program used has a timestamp of December 16, 2023, which is not much different from the version on October 12, 2023. The main change is the modification of the obfuscation character &#8220;_&#8221; in the string to evade detection.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-8.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"164\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-8-1024x164.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29874\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-8-1024x164.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-8-300x48.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-8-768x123.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-8-600x96.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-8-200x32.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-8.png 1222w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption class=\"wp-element-caption\">Figure 8: &nbsp;Partial string obfuscation changes, the right side is the new version<\/figcaption><\/figure>\n<\/div>\n\n\n<p>&nbsp;<\/p>\n\n\n\n<p>TransparentTribe used a version of CrimsonRAT with the version number &#8220;S.F.0.3&#8221; in November 2023, but in this activity, the CrimsonRAT has increased the version number obfuscation, confusing the version number into &#8220;A._E.0._6&#8221;, using this method to evade detection:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-9.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"167\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-9-1024x167.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29876\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-9-1024x167.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-9-300x49.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-9-768x125.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-9-600x98.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-9-200x33.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-9.png 1185w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption class=\"wp-element-caption\">&nbsp;Figure 9: &nbsp;CrimsonRAT version number, the right side is the new version.<\/figcaption><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<p>The version found on October 12 is somewhat different from the previously found versions, adding obfuscation strings &#8220;_&#8221; to a large number of key strings, and all the versions found recently have been done through this string obfuscation method:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-10.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"137\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-10-1024x137.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-29878\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-10-1024x137.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-10-300x40.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-10-768x103.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-10-600x80.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-10-200x27.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Figure-10.png 1130w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption class=\"wp-element-caption\">&nbsp;Figure 10: &nbsp;Comparison of the October 2023 version with earlier versions<\/figcaption><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Attribution of Attackers<\/h2>\n\n\n\n<p>NSFOCUS Security Research Labs found the following attribution items in this APT incident:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The malicious sample used by the attacker is CrimsonRAT, which is one of the Trojans commonly used by TransparentTribe;<\/li>\n\n\n\n<li>The attack process and VBA script used by the attacker in this incident are consistent with the attack chain characteristics and coding habits of TransparentTribe in recent attacks;<\/li>\n\n\n\n<li>The phishing document captured in this incident was uploaded from India, which is consistent with the common attack targets of TransparentTribe;<\/li>\n<\/ul>\n\n\n\n<p>Therefore, NSFOCUS Security Research Labs attributes the attackers of this attack incident to the TransparentTribe group.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">IOC<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>IOC<\/strong><\/td><td><strong>Note<\/strong><\/td><\/tr><tr><td>c2b37effe3195665ec5597afa329f<\/td><td>Recommendation for the award of President&#8217;s.docm<\/td><\/tr><tr><td>f5380e7a6e15a0ef27e6f31fcc29ed4d<\/td><td>itmvroidovs.exe<\/td><\/tr><tr><td>41d801d96c9e27c5ca6c4678ffa2d7e2<\/td><td>Monthly Report MAP.xlam<\/td><\/tr><tr><td>mus09.duckdns.org<\/td><td>C2<\/td><\/tr><tr><td>64.188.21.202:6826<\/td><td>C2<\/td><\/tr><tr><td>64.188.21.202:18828<\/td><td>C2<\/td><\/tr><tr><td>64.188.21.202:22821<\/td><td>C2<\/td><\/tr><tr><td>64.188.21.202:28120<\/td><td>C2<\/td><\/tr><tr><td>164.68.122.64:11128<\/td><td>C2<\/td><\/tr><tr><td>164.68.122.64:18187<\/td><td>C2<\/td><\/tr><tr><td>164.68.122.64:19986<\/td><td>C2<\/td><\/tr><tr><td>164.68.122.64:27684<\/td><td>C2<\/td><\/tr><tr><td>164.68.122.64:25123<\/td><td>C2<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Related blog post: <\/p>\n\n\n\n<p><a href=\"https:\/\/nsfocusglobal.com\/pt-br\/indian-government-agencies-targeted-in-phishing-attacks-by-apt-group-sidecopy\/\" target=\"_blank\" rel=\"noreferrer noopener\">Indian Government Agencies Targeted in Phishing Attacks by APT Group SideCopy <\/a><\/p>\n\n\n\n<p><strong>About NSFOCUS Security Research Labs<\/strong><\/p>\n\n\n\n<p>NSFOCUS Security Research Labs is an internationally recognized cybersecurity research and threat response center at the front of vulnerability assessment, threat hunting and mitigation research.<\/p>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>Overview Leveraging our global threat hunting system, NSFOCUS Security Research Labs discovered spear-phishing email attacks by the APT group TransparentTribe targeting Indian government departments on February 2, 2024. The timing of these attacks coincides with the presidential election in India, scheduled for April-May of this year, and the bait documents are related to the &#8220;President&#8217;s [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":29895,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[3],"tags":[94],"class_list":["post-29861","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-apt-group"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TransparentTribe&#039;s Spear-Phishing Targeting Indian Government Departments - NSFOCUS<\/title>\n<meta name=\"description\" content=\"Discover TransparentTribe&#039;s spear-phishing attacks on Indian government, targeting sensitive data with CrimsonRAT.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TransparentTribe&#039;s Spear-Phishing Targeting Indian Government Departments - NSFOCUS\" \/>\n<meta property=\"og:description\" content=\"Discover TransparentTribe&#039;s spear-phishing attacks on Indian government, targeting sensitive data with CrimsonRAT.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/\" \/>\n<meta property=\"og:site_name\" content=\"NSFOCUS\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-24T03:36:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-17T18:07:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Featured-Image-1.png\" \/>\n<meta name=\"author\" content=\"NSFOCUS\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"TransparentTribe&#039;s Spear-Phishing Targeting Indian Government Departments - NSFOCUS\" \/>\n<meta name=\"twitter:description\" content=\"Discover TransparentTribe&#039;s spear-phishing attacks on Indian government, targeting sensitive data with CrimsonRAT.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Featured-Image-1.png\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"NSFOCUS\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/\"},\"author\":{\"name\":\"NSFOCUS\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\"},\"headline\":\"TransparentTribe&#8217;s Spear-Phishing Targeting Indian Government Departments\",\"datePublished\":\"2024-07-24T03:36:02+00:00\",\"dateModified\":\"2026-04-17T18:07:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/\"},\"wordCount\":1090,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Featured-Image-1.png\",\"keywords\":[\"APT Group;\"],\"articleSection\":[\"Blog\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/\",\"name\":\"TransparentTribe's Spear-Phishing Targeting Indian Government Departments - NSFOCUS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Featured-Image-1.png\",\"datePublished\":\"2024-07-24T03:36:02+00:00\",\"dateModified\":\"2026-04-17T18:07:37+00:00\",\"description\":\"Discover TransparentTribe's spear-phishing attacks on Indian government, targeting sensitive data with CrimsonRAT.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Featured-Image-1.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Featured-Image-1.png\",\"width\":500,\"height\":240,\"caption\":\"Screenshot of a cybersecurity slide highlighting an APT group analysis.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/transparenttribes-spear-phishing-targeting-indian-government-departments\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nsfocusglobal.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TransparentTribe&#8217;s Spear-Phishing Targeting Indian Government Departments\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#website\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/\",\"name\":\"NSFOCUS\",\"description\":\"Security Made Smart and Simple\",\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nsfocusglobal.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\",\"name\":\"NSFOCUS\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"width\":248,\"height\":36,\"caption\":\"NSFOCUS\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\",\"name\":\"NSFOCUS\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"caption\":\"NSFOCUS\"},\"sameAs\":[\"https:\\\/\\\/nsfocusglobal.com\"],\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TransparentTribe's Spear-Phishing Targeting Indian Government Departments - NSFOCUS","description":"Discover TransparentTribe's spear-phishing attacks on Indian government, targeting sensitive data with CrimsonRAT.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/","og_locale":"pt_BR","og_type":"article","og_title":"TransparentTribe's Spear-Phishing Targeting Indian Government Departments - NSFOCUS","og_description":"Discover TransparentTribe&#039;s spear-phishing attacks on Indian government, targeting sensitive data with CrimsonRAT.","og_url":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/","og_site_name":"NSFOCUS","article_published_time":"2024-07-24T03:36:02+00:00","article_modified_time":"2026-04-17T18:07:37+00:00","og_image":[{"url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Featured-Image-1.png","type":"","width":"","height":""}],"author":"NSFOCUS","twitter_card":"summary_large_image","twitter_title":"TransparentTribe's Spear-Phishing Targeting Indian Government Departments - NSFOCUS","twitter_description":"Discover TransparentTribe&#039;s spear-phishing attacks on Indian government, targeting sensitive data with CrimsonRAT.","twitter_image":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Featured-Image-1.png","twitter_misc":{"Escrito por":"NSFOCUS","Est. tempo de leitura":"7 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/#article","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/"},"author":{"name":"NSFOCUS","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d"},"headline":"TransparentTribe&#8217;s Spear-Phishing Targeting Indian Government Departments","datePublished":"2024-07-24T03:36:02+00:00","dateModified":"2026-04-17T18:07:37+00:00","mainEntityOfPage":{"@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/"},"wordCount":1090,"commentCount":0,"publisher":{"@id":"https:\/\/nsfocusglobal.com\/#organization"},"image":{"@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Featured-Image-1.png","keywords":["APT Group;"],"articleSection":["Blog"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/","url":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/","name":"TransparentTribe's Spear-Phishing Targeting Indian Government Departments - NSFOCUS","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/#primaryimage"},"image":{"@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Featured-Image-1.png","datePublished":"2024-07-24T03:36:02+00:00","dateModified":"2026-04-17T18:07:37+00:00","description":"Discover TransparentTribe's spear-phishing attacks on Indian government, targeting sensitive data with CrimsonRAT.","breadcrumb":{"@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/#primaryimage","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Featured-Image-1.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/07\/Featured-Image-1.png","width":500,"height":240,"caption":"Screenshot of a cybersecurity slide highlighting an APT group analysis."},{"@type":"BreadcrumbList","@id":"https:\/\/nsfocusglobal.com\/transparenttribes-spear-phishing-targeting-indian-government-departments\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nsfocusglobal.com\/"},{"@type":"ListItem","position":2,"name":"TransparentTribe&#8217;s Spear-Phishing Targeting Indian Government Departments"}]},{"@type":"WebSite","@id":"https:\/\/nsfocusglobal.com\/#website","url":"https:\/\/nsfocusglobal.com\/","name":"NSFOCUS","description":"Security Made Smart and Simple","publisher":{"@id":"https:\/\/nsfocusglobal.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nsfocusglobal.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/nsfocusglobal.com\/#organization","name":"NSFOCUS","url":"https:\/\/nsfocusglobal.com\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/logo\/image\/","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","width":248,"height":36,"caption":"NSFOCUS"},"image":{"@id":"https:\/\/nsfocusglobal.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d","name":"NSFOCUS","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","caption":"NSFOCUS"},"sameAs":["https:\/\/nsfocusglobal.com"],"url":"https:\/\/nsfocusglobal.com\/pt-br\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/29861","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/comments?post=29861"}],"version-history":[{"count":0,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/29861\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media\/29895"}],"wp:attachment":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media?parent=29861"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/categories?post=29861"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/tags?post=29861"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}