Also known as: APT36, ProjectM, MYTHIC LEOPARD, tracked as, MYTHIC Leopard, ZPHP, HANEYMANEY, LandUpdate808, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, auto-masking, Kongtuke, UNC6619
TAG-140 operates primarily against Indian government entities with an overarching espionage mandate. The group has refined its delivery mechanisms over time, moving from generic spearphishing attachments to sophisticated ClickFix‑style social engineering lures that redirect victims to counterfeit Government of India Ministry pages. These lures trigger a malicious mshta.exe payload that installs the Broadaspect loader, which in turn deploys a Delphi‑compiled RAT family – currently dominated by DRAT V2. DRAT V2 enhances adversary foothold with advanced command and scripting capabilities, enabling arbitrary Windows shell execution, bidirectional file transfer between infected hosts and the actor’s custom TCP C2, and robust data staging for exfiltration. The RAT also leverages known software vulnerabilities (e.g., in WinRAR) for privilege escalation and supports lateral movement across victim networks through its built‑in command set. The threat actor demonstrates iterative malware evolution, incorporating new delivery vectors, persistence techniques, and post‑exploitation capabilities while maintaining a modular structure that eases detection evasion. While the group’s primary goal remains information gathering from Indian government sectors, evidence suggests expansion of targets to include defense contractors and critical infrastructure firms, expanding its operational footprint. Although attribution is reasonably grounded in common technical indicators, some contextual gaps remain—most notably a clear timeline of activity and concrete business objectives beyond espionage. Nevertheless, the consistent use of shared tool families (DRAT V2, BroaderAspect) and persistent spearphishing infrastructure strongly support continued profiling and defensive focus on this adversary cluster.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TAG-140, also known as APT36 or Mythic Leopard, is a sophisticated cyber‑espionage actor focused on Indian government and defense organizations. The group deploys a custom Delphi‑compiled RAT (DRAT V2) via ClickFix‑style social engineering lures that trigger mshta.exe executions, establishing persistence through the BroaderAspect loader. Their campaigns feature a proprietary TCP C2 channel, bidirectional file transfer, and repeated use of spearphishing attachments to advance staging and exfiltration.
Goals & Targeting
TAG‑140’s strategic objective is to acquire privileged intelligence from Indian government and defense entities, likely for geopolitical advantage. Their targeting pattern shows a preference for high‑value institutional sectors—government, defense, critical infrastructure, energy, and finance—while occasionally extending into adjacent domains such as maritime, telecommunications and education. The use of spearphishing with highly tailored lure content indicates intent to maximize infiltration success, enabling long‑term persistence for sustained intelligence gathering.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
10
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
6
Tactics