Transparent Tribe

APT / StateG0134 ↗
Origin🇮🇳 Índia
Techniques (MITRE ATT&CK)14
SourceMITRE ATT&CK
State sponsor: PakistanAttribution confidence: 50%Target categories: Civil society, Military, Government
Also known as:APT 36APT36C-MajorCOPPER FIELDSTONEEarth KarkaddanGreen HavildarMythic LeopardProjectMStorm-0156TMP.Lapis

About the group

Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity39
Impact: High
T1189ENTRYInitial accessDrive-byCompromiseEXECExecutionVisual Basic

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 14

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 2

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 169

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha256_hashd7fea5f6217db6e04f75333a65a46cdfcc523c7f3ddc29cfaecb18cd8876ea98NjRATthreatfox
md5_hash1cf8cce965f8f2089ce67ef811b29d13NjRATthreatfox
sha1_hashca868ac1e4f42282fb74865fc2f9edf38b052e4bNjRATthreatfox
sha1_hash19dc42491a499830d7638933b5f457740ffce395NjRATthreatfox
md5_hash1742ad51f743c9e518abec7fc6f9451bNjRATthreatfox
sha256_hashd5c4983535d57d69fc6f8c09ff4a3838d6a61ac6b149de67b89c0c062968d9cdNjRATthreatfox
ip:port81.71.128.221:14149NjRATthreatfox
ip:port156.223.213.38:1177NjRATthreatfox
ip:port188.132.242.67:8731DarkCometthreatfox
ip:port87.243.97.168:100DarkCometthreatfox
ip:port188.132.242.67:8087DarkCometthreatfox
ip:port188.209.158.187:1177NjRATthreatfox
ip:port156.223.177.158:1177NjRATthreatfox
ip:port172.94.46.114:1012NjRATthreatfox
sha1_hashb5abd48cdb1d3f97418047505d5a32e03e694fe5NjRATthreatfox
md5_hash2a85f2e5876b278a7af9393483de455bNjRATthreatfox
sha256_hashbae4f4322d4c215be01990ad77275474f829ed7b3731703ed07946ab9d041413NjRATthreatfox
ip:port105.72.55.52:8080NjRATthreatfox
ip:port8.148.27.183:12050NjRATthreatfox
domainjoaoszr3.ddns.netNjRATthreatfox
domainzenvyus.ddns.netNjRATthreatfox
domainfouad-94.myq-see.comNjRATthreatfox
ip:port69.40.43.85:1604DarkCometthreatfox
ip:port74.162.154.113:1604DarkCometthreatfox
ip:port87.243.97.168:1604DarkCometthreatfox
ip:port187.101.57.177:1177NjRATthreatfox
sha1_hashfd7ec45552919baf92c37cb17b533d5eedfe5758NjRATthreatfox
md5_hash01af93c099eda51a2b46fb2108fc1e2aNjRATthreatfox
sha256_hashf9ac08dc0d9d265ba44e7b256cc554cd9a741ca2a7e4dc01807376a90f8b1024NjRATthreatfox
ip:port8.148.23.144:12329NjRATthreatfox

+169 indicators in total. See them all on the IOCs page.

Transparent Tribe uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →