Also known as: C-Major, Transparent Tribe, Mythic Leopard, ProjectM, APT36, APT 36, TMP.Lapis, Green Havildar, COPPER FIELDSTONE, Earth Karkaddan, Storm-0156, APT34, Earth Preta, Stately Taurus, EarthKarkaddan, military personnel, a Pakistan-linked threat actor, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, APT28, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Desert Falcon, Arid Viper, Bearded Barbie, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, ETHEREAL PANDA, Soft Cell, Alloy Taurus, Red Moros, Othorene
Operation C‑Major, also known as Transparent Tribe or Earth Karkaddan, has operated since at least 2013, primarily targeting Indian military, diplomatic, and academic institutions. The group uses a blend of psychological manipulation and technical exploits to deliver malware. At the initial stage investigators frequently observe spear‑phishing emails that contain malicious ZIP files—packed with disguised LNK shortcuts, PowerShell scripts, and .NET executables—which are designed to bypass user scrutiny through fake recruitment adverts for Cabinet Secretariat positions. Once executed, the actor deploys a suite of remote access trojans such as CrimsonRAT, MSIL/Crimson, CapraRAT, and custom‑built SheetAgent RAT. These tools provide full‑control capabilities, exfiltration channels (notably using Google Sheets as an unconventional command‑and‑control channel), and robust persistence via scheduled tasks and startup folder entries. To evade detection the malware includes extensive anti‑analysis routines targeting virtualized environments. In addition to Windows‑focused campaigns, C‑Major extends its reach to Android devices through AndroRAT variants like StealthAgent and AhMyth, which mimic legitimate applications (e.g., YouTube) to harvest communications, location data, and credentials. The group also leverages waterhole attacks on government portals and exploits vulnerabilities such as Adobe Reader to deliver spyware. Operationally, the actor maintains a steady tempo of campaigns across multiple sectors in India and occasionally in other Asian countries, demonstrating an intent to collect strategic intelligence for geopolitical objectives tied to Pakistan‑India affairs.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Operation C‑Major (APT36) is a Pakistani‑linked cyber espionage group that targets Indian government, defense, and education entities using sophisticated social engineering and malware delivery tactics. The actor routinely employs spear‑phishing emails, fake recruitment advertisements, waterhole sites, and cross‑platform backdoors to gain persistent access and exfiltrate data via custom RATs such as CrimsonRAT, CapraRAT, and SheetAgent. Its operations are adaptive, leveraging both Windows and Android platforms while incorporating anti‑analysis defenses and multiple persistence methods.
Goals & Targeting
Operation C‑Major’s strategic goal is state‑level espionage aimed at gathering actionable intelligence on Indian defense, political, and civil society actors. By infiltrating government ministries, army branches, educational institutions, and related organizations, the group seeks privileged access‑to information such as communications, plans, budgets, and personnel data that could influence broader regional power dynamics. The use of social engineering and legitimate business lures indicates a preference for low‑profile operations that reduce attribution risk while maximizing data harvest.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
C‑Major consistently targets Indian military and diplomatic entities through a mix of spear‑phishing, waterhole, and fake job advertisement campaigns. The actor has demonstrated a rapid operational tempo, launching new variants every few months between 2021 and 2024, with particular focus on defense portfolios, educational institutions, and research think tanks. Notable operations include the 2023 campaign against the Indian Ministry of Defence and earlier phishing campaigns that used Adobe Reader exploits to drop spyware on government computers. The group's persistence mechanisms (scheduled tasks, startup folders) and anti‑analysis code reveal a mature threat actor capable of maintaining long‑term footholds when needed.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The evidence base for Operation C‑Major is drawn from multiple security research reports, phishing incident logs, and malware samples, giving moderate confidence in its identity as a Pakistani‑linked APT group targeting India. While attribution claims are supported by consistent tactics, techniques, and shared infrastructure, the exact timeline of operations remains uncertain due to limited public disclosure of dates for many incidents. Detailed technical provenance (e.g., linking all variants conclusively) is still incomplete, leaving gaps in understanding the full scope of its capabilities and long‑term objectives.
No campaigns linked yet.
No observed data linked yet.
16
Techniques
53
Tools
0
Campaigns
38
IOCs
0
Observed Data
5
Tactics