Also known as: COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM, C-Major, Transparent Tribe, APT 36, TMP.Lapis, Green Havildar, Earth Karkaddan, Storm-0156
Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.(Citation: Proofpoint Operation Transparent Tribe March 2016)(Citation: Kaspersky Transparent Tribe August 2020)(Citation: Talos Transparent Tribe May 2021)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Transparent Tribe, also known as COPPER FIELDSTONE or APT36, is an advanced persistent threat (APT) group suspected to be based in Pakistan. Primarily involved in espionage activities, the group has targeted government and defense sectors in India and Afghanistan since at least 2013. Known for using sophisticated tactics such as spear-phishing campaigns, malware deployment, and domain spoofing, Transparent Tribe poses a significant risk to diplomatic and military organizations.
Goals & Targeting
Transparent Tribe's primary motivation appears to be espionage, focusing on gathering sensitive information from government and defense sectors. The targeting of specific countries like India and Afghanistan suggests a strategic interest in South Asian geopolitical dynamics. The group likely aims to achieve long-term access to critical infrastructure to facilitate intelligence collection, influence decision-making processes, or support national security interests.
Enhanced Description
Transparent Tribe is a state-sponsored APT group that has been operational since at least 2013. The group primarily targets government institutions, defense organizations, and research entities in India and Afghanistan, with suspected ties to Pakistan due to geographical activity patterns and targeting focus. Transparent Tribe's operations are characterized by the use of cyber espionage tools such as DarkComet, ObliqueRAT, and njRAT. These tools enable the group to gain unauthorized access, collect sensitive information, and exfiltrate data from targeted systems. The group has been linked to multiple campaigns that involve encrypted communications, domain spoofing, and file-based attacks, leveraging techniques such as Visual Basic scripting and Hidden File/Directories to maintain persistence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Transparent Tribe has conducted several campaigns targeting South Asian diplomatic and defense institutions. The group's operational tempo appears to be event-driven, with increased activity during key geopolitical events. Notable campaigns include Operation Transparent Tribe, which involved spear-phishing attacks using encrypted files and malicious macros to compromise systems in India.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the group's existence due to multiple intelligence reports. Specific campaign details and exact origin remain uncertain.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
14
Techniques
5
Tools
0
Campaigns
0
IOCs
0
Observed Data
5
Tactics