Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors operation c-major

Also known as: C-Major, Transparent Tribe, Mythic Leopard, ProjectM, APT36, APT 36, TMP.Lapis, Green Havildar, COPPER FIELDSTONE, Earth Karkaddan, Storm-0156, APT34, Earth Preta, Stately Taurus, EarthKarkaddan, military personnel, a Pakistan-linked threat actor, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, APT28, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Desert Falcon, Arid Viper, Bearded Barbie, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, ETHEREAL PANDA, Soft Cell, Alloy Taurus, Red Moros, Othorene

Description

Operation C‑Major, also known as Transparent Tribe or Earth Karkaddan, has operated since at least 2013, primarily targeting Indian military, diplomatic, and academic institutions. The group uses a blend of psychological manipulation and technical exploits to deliver malware. At the initial stage investigators frequently observe spear‑phishing emails that contain malicious ZIP files—packed with disguised LNK shortcuts, PowerShell scripts, and .NET executables—which are designed to bypass user scrutiny through fake recruitment adverts for Cabinet Secretariat positions. Once executed, the actor deploys a suite of remote access trojans such as CrimsonRAT, MSIL/Crimson, CapraRAT, and custom‑built SheetAgent RAT. These tools provide full‑control capabilities, exfiltration channels (notably using Google Sheets as an unconventional command‑and‑control channel), and robust persistence via scheduled tasks and startup folder entries. To evade detection the malware includes extensive anti‑analysis routines targeting virtualized environments. In addition to Windows‑focused campaigns, C‑Major extends its reach to Android devices through AndroRAT variants like StealthAgent and AhMyth, which mimic legitimate applications (e.g., YouTube) to harvest communications, location data, and credentials. The group also leverages waterhole attacks on government portals and exploits vulnerabilities such as Adobe Reader to deliver spyware. Operationally, the actor maintains a steady tempo of campaigns across multiple sectors in India and occasionally in other Asian countries, demonstrating an intent to collect strategic intelligence for geopolitical objectives tied to Pakistan‑India affairs.

Goals & Targeting

Targeted Sectors

Government
Education
Defense
Telecommunications
Non profit
Financial services
Energy
Think tank
Media
Healthcare
Aerospace
Manufacturing
Transportation
Critical infrastructure
Pharmaceutical
Maritime
Legal services
Information technology
Chemical
Nuclear
Aviation
Entertainment
Hospitality
Utilities
Mining

Targeted Countries / Regions

British Indian Ocean Territory
India
RU
US
CN
UA
PK
IN
AE
IL
VN
BY
KR
SA
PL
LB
TR
IR
KZ
JP
TW
IQ
DE
IT
FR
GB
RO

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Operation C‑Major (APT36) is a Pakistani‑linked cyber espionage group that targets Indian government, defense, and education entities using sophisticated social engineering and malware delivery tactics. The actor routinely employs spear‑phishing emails, fake recruitment advertisements, waterhole sites, and cross‑platform backdoors to gain persistent access and exfiltrate data via custom RATs such as CrimsonRAT, CapraRAT, and SheetAgent. Its operations are adaptive, leveraging both Windows and Android platforms while incorporating anti‑analysis defenses and multiple persistence methods.

Goals & Targeting

Operation C‑Major’s strategic goal is state‑level espionage aimed at gathering actionable intelligence on Indian defense, political, and civil society actors. By infiltrating government ministries, army branches, educational institutions, and related organizations, the group seeks privileged access‑to information such as communications, plans, budgets, and personnel data that could influence broader regional power dynamics. The use of social engineering and legitimate business lures indicates a preference for low‑profile operations that reduce attribution risk while maximizing data harvest.

Enhanced Description

Key Capabilities

  • Social engineering
  • Phishing (spear‑phishing)
  • Malware deployment via backdoors
  • CrimsonRAT
  • AndroRAT
  • MSIL/Crimson
  • CapraRAT
  • ObliqueRat
  • StealthAgent
  • AhMyth Android RAT
  • Custom remote access trojan
  • Watering hole attacks
  • USB worm delivery
  • Android spyware mimicking YouTube (Capra Tube)
  • Adobe Reader exploit
  • Fake recruitment advertisement lure
  • Malicious ZIP archive with LNK, PowerShell script, .NET executable
  • ControlR remote management tool usage
  • SheetAgent RAT using Google Sheets C2
  • Persistence via scheduled tasks and startup folder
  • Anti‑analysis / anti‑VM checks

MITRE ATT&CK Tactics

Initial Access
Execution
Ingress Tool Transfer
Command and Control
Exfiltration
Persistence

ATT&CK Techniques

T1566
T1566.001
T1203
T1189
T1071.001
T1041
T1204.002
T1105

Software / Tooling

CrimsonRAT
AndroRAT
MSIL/Crimson RAT
CapraRAT
ObliqueRat
StealthAgent
AhMyth Android RAT
ControlR remote management tool
SheetAgent RAT
Capra Tube

Campaigns & Victims

C‑Major consistently targets Indian military and diplomatic entities through a mix of spear‑phishing, waterhole, and fake job advertisement campaigns. The actor has demonstrated a rapid operational tempo, launching new variants every few months between 2021 and 2024, with particular focus on defense portfolios, educational institutions, and research think tanks. Notable operations include the 2023 campaign against the Indian Ministry of Defence and earlier phishing campaigns that used Adobe Reader exploits to drop spyware on government computers. The group's persistence mechanisms (scheduled tasks, startup folders) and anti‑analysis code reveal a mature threat actor capable of maintaining long‑term footholds when needed.

IOC Patterns

  • phishing email attachments
  • malicious ZIP file with LNK/PowerShell/.NET
  • domains such as sharingmymedia.com, viral91.xyz, demo-cloud.space, TMP.Lapis
  • IP addresses 209.127.19.241, 5.189.145.248, 173.212.206.227
  • file hashes SHA‑256 and SHA‑1 of known samples

Recommended Actions

  • Implement advanced endpoint protection capable of detecting RAT activity such as CrimsonRAT and ControlR; Block or monitor malicious domains (e.g., sharingmymedia.com, viral91.xyz) via DNS filtering; Apply rigorous email filtering and user training to mitigate spear‑phishing and suspicious attachments; Restrict usage of removable USB media or enforce automated scanning for embedded malware; Monitor Android devices for unauthorized apps resembling legitimate services (YouTube, etc.) and deploy mobile device management controls; Detect and remediate persistent backdoors via scheduled tasks and startup folder monitoring; Enforce least privilege and monitor PowerShell executions for anomalous activity; Incorporate virtual‑machine detection checks to identify anti‑analysis evasion attempts.

Suggested Tags

Cyber Espionage
Social Engineering
Phishing
Backdoor
CrimsonRAT
AndroRAT
Spear Phishing
Malicious Email
Remote Access Trojan
Adobe Reader Exploit
Watering Hole
Indian Government Target
Pakistani Threat Actor
Custom Malware (MSIL/Crimson)
Android Spyware
APT36
Operation C‑Major
Earth Karkaddan
ObliqueRat
StealthAgent
AhMyth
USB Worm
Indian Defence Sector
Job Recruitment Ads

Confidence Assessment

The evidence base for Operation C‑Major is drawn from multiple security research reports, phishing incident logs, and malware samples, giving moderate confidence in its identity as a Pakistani‑linked APT group targeting India. While attribution claims are supported by consistent tactics, techniques, and shared infrastructure, the exact timeline of operations remains uncertain due to limited public disclosure of dates for many incidents. Detailed technical provenance (e.g., linking all variants conclusively) is still incomplete, leaving gaps in understanding the full scope of its capabilities and long‑term objectives.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 3 Domain 11 SHA-1 Hash 5 IPv4 Address 1

References

  1. www.eset.com — Cited by web research for: APT34
  2. docs.rapid7.com — Cited by web research for: T1583
  3. apt.etda.or.th — Cited by web research for: CapraRAT
  4. www.sentinelone.com — Cited by web research for: signed.apk
  5. www.trendmicro.com — Cited by web research for: dlrarhsiva.exe
  6. https://www.precursorintelligence.com/threat-actors/operation-c-major — Cited by AI analysis.
  7. https://www.proofpoint.com/sites/default/files/proofpoint-operation-transparent-tribe-threat-insight-en.pdf — Cited by AI analysis.
  8. https://news.softpedia.com/news/another-case-of-a-pakistani-apt-spying-on-indian-military-personnel-502093.shtml — Cited by AI analysis.
  9. https://blog.trendmicro.com/trendlabs-security-intelligence/operation-c-major-actors-also-used-android-blackberry-mobile-spyware-targets/ — Cited by AI analysis.
  10. https://cysinfo.com/cyber-attack-targeting-cbi-and-possibly-indian-army-officials/ — Cited by AI analysis.
  11. https://blog.yoroi.company/research/transparent-tribe-four-years-later/ — Cited by AI analysis.
  12. https://blog.malwarebytes.com/threat-analysis/2020/03/apt36-jumps-on-the-coronavirus-bandwagon-delivers-crimson-rat/ — Cited by AI analysis.
  13. https://www.seqrite.com/blog/operation-honey-trap-apt36-targets-defense-organizations-in-india/ — Cited by AI analysis.
  14. https://blog.talosintelligence.com/2022/03/transparent-tribe-new-campaign.html — Cited by AI analysis.
  15. https://blog.talosintelligence.com/2022/07/transparent-tribe-targets-education.html — Cited by AI analysis.
  16. https://www.welivesecurity.com/2023/03/07/love-scam-espionage-transparent-tribe-lures-indian-pakistani-officials/ — Cited by AI analysis.
  17. https://www.sentinelone.com/labs/transparent-tribe-apt36-pakistan-aligned-threat-actor-expands-interest-in-indian-education-sector/ — Cited by AI analysis.
  18. https://www.sentinelone.com/labs/capratube-transparent-tribes-caprarat-mimics-youtube-to-hijack-android-phones/ — Cited by AI analysis.
  19. https://blog.checkpoint.com/research/the-evolution-of-transparent-tribes-new-malware/ — Cited by AI analysis.
  20. https://blogs.blackberry.com/en/2024/05/transparent-tribe-targets-indian-government-defense-and-aerospace-sectors — Cited by AI analysis.
  21. https://www.sentinalone.com/labs/capratube-remix-transparent-tribes-android-spyware-targeting-gamers-weapons-enthusiasts/ — Cited by AI analysis.
  22. https://hunt.io/blog/apt36-clickfix-campaign-indian-ministry-of-defence — Cited by AI analysis.

Intel Summary

16

Techniques

53

Tools

0

Campaigns

38

IOCs

0

Observed Data

5

Tactics

Tags

APT
Government Targeting
espionage
government-sector
india
cyber-espionage
Cyber Espionage
Social Engineering
Phishing
Backdoor
CrimsonRAT
AndroRAT
Spear Phishing
Malicious Email
Remote Access Trojan
Adobe Reader Exploit
Watering Hole
Indian Government Target
Pakistani Threat Actor
Custom Malware (MSIL/Crimson)
Android Spyware
APT36
Operation C‑Major
Earth Karkaddan
ObliqueRat
StealthAgent
AhMyth
USB Worm
Indian Defence Sector
Job Recruitment Ads

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
P
Confidence
55%
Added
Jul 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.