Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TAG-140

Also known as: APT36, ProjectM, MYTHIC LEOPARD, tracked as, MYTHIC Leopard, ZPHP, HANEYMANEY, LandUpdate808, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, auto-masking, Kongtuke, UNC6619

Description

TAG-140 operates primarily against Indian government entities with an overarching espionage mandate. The group has refined its delivery mechanisms over time, moving from generic spearphishing attachments to sophisticated ClickFix‑style social engineering lures that redirect victims to counterfeit Government of India Ministry pages. These lures trigger a malicious mshta.exe payload that installs the Broadaspect loader, which in turn deploys a Delphi‑compiled RAT family – currently dominated by DRAT V2. DRAT V2 enhances adversary foothold with advanced command and scripting capabilities, enabling arbitrary Windows shell execution, bidirectional file transfer between infected hosts and the actor’s custom TCP C2, and robust data staging for exfiltration. The RAT also leverages known software vulnerabilities (e.g., in WinRAR) for privilege escalation and supports lateral movement across victim networks through its built‑in command set. The threat actor demonstrates iterative malware evolution, incorporating new delivery vectors, persistence techniques, and post‑exploitation capabilities while maintaining a modular structure that eases detection evasion. While the group’s primary goal remains information gathering from Indian government sectors, evidence suggests expansion of targets to include defense contractors and critical infrastructure firms, expanding its operational footprint. Although attribution is reasonably grounded in common technical indicators, some contextual gaps remain—most notably a clear timeline of activity and concrete business objectives beyond espionage. Nevertheless, the consistent use of shared tool families (DRAT V2, BroaderAspect) and persistent spearphishing infrastructure strongly support continued profiling and defensive focus on this adversary cluster.

Goals & Targeting

Targeted Sectors

Government
Defense
Critical infrastructure
Legal services
Financial services
Mining
Healthcare
Energy
Education
Maritime
Telecommunications
Non profit
Aerospace
Hospitality
Oil gas
Transportation
Gaming
Aviation
Manufacturing
Retail
Think tank

Targeted Countries / Regions

US
TW
PK
SA
CN
IN
BR
MX
DE
JP
AE
PL
IT
KR
VN
NG
IL
ES
UA

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 15 hours ago

Executive Summary

TAG-140, also known as APT36 or Mythic Leopard, is a sophisticated cyber‑espionage actor focused on Indian government and defense organizations. The group deploys a custom Delphi‑compiled RAT (DRAT V2) via ClickFix‑style social engineering lures that trigger mshta.exe executions, establishing persistence through the BroaderAspect loader. Their campaigns feature a proprietary TCP C2 channel, bidirectional file transfer, and repeated use of spearphishing attachments to advance staging and exfiltration.

Goals & Targeting

TAG‑140’s strategic objective is to acquire privileged intelligence from Indian government and defense entities, likely for geopolitical advantage. Their targeting pattern shows a preference for high‑value institutional sectors—government, defense, critical infrastructure, energy, and finance—while occasionally extending into adjacent domains such as maritime, telecommunications and education. The use of spearphishing with highly tailored lure content indicates intent to maximize infiltration success, enabling long‑term persistence for sustained intelligence gathering.

Enhanced Description

Key Capabilities

  • Remote access trojan (RAT) deployment including DRAT V2, CurlBack and SparkRAT
  • Custom TCP‑based command‑and‑control protocol
  • Initial access via ClickFix‑style social engineering lure using mshta.exe and HTA/MSI attachments
  • Installer loader (BroaderAspect) establishing persistence
  • Arbitrary Windows shell command execution with output capture
  • Enhanced file system interaction and data staging for exfiltration
  • Spearphishing campaigns targeting Indian government entities
  • Exploitation of software vulnerabilities such as WinRAR for privilege escalation
  • Lateral movement across victim networks utilizing built‑in command set
  • Bidirectional file transfer between infected host and C2 (payload upload / exfiltration)
  • Use of Delphi‑compiled RATs for system reconnaissance

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.recordedfuture.com — Cited by web research for: MYTHIC Leopard
  2. www.recordedfuture.com — Cited by web research for: ZPHP
  3. attack.mitre.org — Cited by web research for: Advanced Persistent Threat 39
  4. unit42.paloaltonetworks.com — Cited by web research for: Interception
  5. attack.mitre.org — Cited by web research for: systemd
  6. www.rapid7.com — Cited by web research for: CVE-2026-16232

Intel Summary

10

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

6

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Data Exfiltration
Government Targeting
Cyber Espionage
Government Sector
India

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
P
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.