BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

India Defense Sector Targeted by Pakistan-Linked RAT Campaigns

Pakistan-linked hackers deploy advanced malware in cyber espionage attacks on Indian defense targets.

  • Indian defense and government organizations have been targeted by sophisticated cyber espionage campaigns since at least February 2026.
  • Pakistan-aligned threat groups SideCopy and APT36 are deploying malware like Geta RAT, Ares RAT, and DeskRAT to steal data and maintain persistent access.
  • The attacks employ phishing emails with malicious links to deploy multi-stage payloads on both Windows and Linux systems.
  • These campaigns focus on stealth and long-term access by using memory-resident techniques and trusted regional infrastructure.

In a cybersecurity development of significant regional concern, India’s defense sector and government-aligned organizations have been subjected to a wave of espionage campaigns using advanced remote access trojans designed for long-term data theft. These operations, occurring as recent as February 2026, are attributed to sophisticated threat actors with suspected ties to Pakistan.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

According to a report by Aryaka Vice President Aditya K. Sood, the threat groups Transparent Tribe (APT36) and its subdivision SideCopy are refining their espionage approach without major reinvention. “They are refining it,” Sood noted, emphasizing the actors’ focus on operational stealth and cross-platform capability.

Consequently, their methods leverage initial phishing emails that deliver malicious attachments like Windows shortcuts and PowerPoint Add-Ins. These then trigger multi-stage infection chains that deploy the final malware payloads, a tactic detailed by researcher Sathwik Ram Prakki on social media.

The primary malware includes Geta RAT for Windows, which can harvest credentials, capture screenshots, and exfiltrate data from USB devices. Meanwhile, a Linux variant uses a Go binary to drop a Python-based Ares RAT with similar post-compromise capabilities.

Another campaign, documented by Sekoia and QiAnXin XLab earlier, delivers a Golang malware called DeskRAT via rogue PowerPoint files. This persistent focus underscores an evolving toolkit for high-value targets within India’s strategic and critical infrastructure sectors.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Warren Probes MrBeast Over App Coaching Kids on Crypto

Senator Elizabeth Warren sent a 12-page letter to MrBeast and Beast Industries CEO Jeff...

SpaceX, xAI Seeking $75B Ahead of Largest IPO Ever

SpaceX is preparing a historic joint IPO with xAI that could file this week,...

CoinShares Files for New ‘Fear Index’ Bitcoin ETFs

CoinShares has filed to launch three novel ETFs specifically tracking Bitcoin volatility, a first...

Visa Joins Canton as Blockchain Super Validator

Financial giant VISA has joined the blockchain-based Canton Network as a super validator, actively...

Bitcoin Stalls at $72K as Onchain Demand Weakens

Bitcoin investors across all wallet sizes are distributing holdings rather than accumulating, a bearish...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading