Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Transparent Tribe

Also known as: COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM, C-Major, Transparent Tribe, APT 36, TMP.Lapis, Green Havildar, Earth Karkaddan, Storm-0156

Description

Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.(Citation: Proofpoint Operation Transparent Tribe March 2016)(Citation: Kaspersky Transparent Tribe August 2020)(Citation: Talos Transparent Tribe May 2021)

Goals & Targeting

Targeted Sectors

Government
Defense

Targeted Countries / Regions

IN

AI Analysis

· 1 week ago

Executive Summary

Transparent Tribe, also known as COPPER FIELDSTONE or APT36, is an advanced persistent threat (APT) group suspected to be based in Pakistan. Primarily involved in espionage activities, the group has targeted government and defense sectors in India and Afghanistan since at least 2013. Known for using sophisticated tactics such as spear-phishing campaigns, malware deployment, and domain spoofing, Transparent Tribe poses a significant risk to diplomatic and military organizations.

Goals & Targeting

Transparent Tribe's primary motivation appears to be espionage, focusing on gathering sensitive information from government and defense sectors. The targeting of specific countries like India and Afghanistan suggests a strategic interest in South Asian geopolitical dynamics. The group likely aims to achieve long-term access to critical infrastructure to facilitate intelligence collection, influence decision-making processes, or support national security interests.

Enhanced Description

Transparent Tribe is a state-sponsored APT group that has been operational since at least 2013. The group primarily targets government institutions, defense organizations, and research entities in India and Afghanistan, with suspected ties to Pakistan due to geographical activity patterns and targeting focus. Transparent Tribe's operations are characterized by the use of cyber espionage tools such as DarkComet, ObliqueRAT, and njRAT. These tools enable the group to gain unauthorized access, collect sensitive information, and exfiltrate data from targeted systems. The group has been linked to multiple campaigns that involve encrypted communications, domain spoofing, and file-based attacks, leveraging techniques such as Visual Basic scripting and Hidden File/Directories to maintain persistence.

Key Capabilities

  • Crimson
  • DarkComet
  • ObliqueRAT
  • Peppy
  • njRAT

MITRE ATT&CK Tactics

Collection
Exfiltration
Persistent Access

ATT&CK Techniques

T1059.003
T1204.002
T1568
T1203
T1189

Software / Tooling

DarkComet
ObliqueRAT
njRAT

Campaigns & Victims

Transparent Tribe has conducted several campaigns targeting South Asian diplomatic and defense institutions. The group's operational tempo appears to be event-driven, with increased activity during key geopolitical events. Notable campaigns include Operation Transparent Tribe, which involved spear-phishing attacks using encrypted files and malicious macros to compromise systems in India.

IOC Patterns

  • Spear-phishing campaigns leveraging Visual Basic scripting
  • Encrypted/encoded communication channels
  • Malicious Office documents

Recommended Actions

  • Implement advanced phishing detection solutions
  • Monitor for encrypted or unusual file activities
  • Conduct regular network traffic analysis
  • Patch systems and maintain updated software versions

Suggested Tags

APT
espionage
government-sector

Confidence Assessment

High confidence in the group's existence due to multiple intelligence reports. Specific campaign details and exact origin remain uncertain.

ATT&CK Techniques

Execution
4 techniques
Initial Access
3 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Crowdstrike Mythic Leopard Profile — Crowdstrike. (n.d.). Mythic Leopard. Retrieved October 6, 2021.
  2. Kaspersky Transparent Tribe August 2020 — Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.
  3. Unit 42 ProjectM March 2016 — Falcone, R. and Conant S. (2016, March 25). ProjectM: Link Found Between Pakistani Actor and Operation Transparent Tribe. Retrieved September 2, 2021.
  4. Proofpoint Operation Transparent Tribe March 2016 — Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.
  5. Talos Transparent Tribe May 2021 — Malhotra, A. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal. Retrieved September 2, 2021.
  6. Secureworks COPPER FIELDSTONE Profile — Secureworks. (n.d.). COPPER FIELDSTONE. Retrieved October 6, 2021.

Intel Summary

14

Techniques

5

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

APT
Government Targeting
espionage
government-sector

Details

MITRE ID
G0134
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
P
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--e44e0985-bc65-4a8f-b578-211c858128e3
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.