Transparent Tribe

APT / StateG0134
Origin🇮🇳 Índia
Techniques (MITRE ATT&CK)14
SourceMITRE ATT&CK
State sponsor: PakistanAttribution confidence: 50%Target categories: Civil society, Military, Government
Also known as:APT 36APT36C-MajorCOPPER FIELDSTONEEarth KarkaddanGreen HavildarMythic LeopardProjectMStorm-0156TMP.Lapis

Vexday analysis

Transparent Tribe (também conhecido como APT36, Mythic Leopard, ProjectM e COPPER FIELDSTONE) é um grupo de ameaça persistente avançada de origem suspeita no Paquistão, ativo desde pelo menos 2013, com atuação voltada principalmente a organizações diplomáticas, de defesa e de pesquisa na Índia e no Afeganistão. Catalogado pelo MITRE ATT&CK sob o identificador G0134, o grupo possui 14 técnicas documentadas na matriz e está associado à exploração de 2 CVEs conhecidas.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity39
Impact: High
T1189ENTRYInitial accessDrive-byCompromiseEXECExecutionVisual Basic

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 14

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 2

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 82

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port2.56.165.157:991NjRATthreatfox
ip:port82.153.241.181:1604DarkCometthreatfox
ip:port47.122.115.225:13152NjRATthreatfox
ip:port129.208.124.105:1177NjRATthreatfox
ip:port79.100.86.116:1604DarkCometthreatfox
ip:port207.189.23.198:1024DarkCometthreatfox
ip:port189.150.106.61:2320DarkCometthreatfox
ip:port170.244.195.143:3000DarkCometthreatfox
sha256_hash33211c0e7a7b9545c13addcd452b68ab0f72b2d5fad857a7a3dd75c34a3fff09njratmalwarebazaar
ip:port47.122.116.54:13676NjRATthreatfox
sha1_hash70c24a2bb97c0b995bce9c7cee42d1cc856d177bNjRATthreatfox
md5_hashac061db892ad8cd21a565996bdb33d5cNjRATthreatfox
sha256_hash135732f938ca6b6e1fd1974ba172665d3c474b5346e035ea24c37b03500fb4e9NjRATthreatfox
sha256_hash135732f938ca6b6e1fd1974ba172665d3c474b5346e035ea24c37b03500fb4e9njratmalwarebazaar
sha1_hash2f6e93b860cef097c863668b1f38a6f7088bcb77NjRATthreatfox
md5_hashb9fbf6f35099d3dd0f984ffb7e027b35NjRATthreatfox
sha256_hash06185d74edbdc06f99095e96f74aa2e49a1cda2d02a294c11a9ac35a0231075eNjRATthreatfox
ip:port86.109.75.132:7777DarkCometthreatfox
ip:port176.129.203.146:1604DarkCometthreatfox
ip:port105.100.163.183:1604DarkCometthreatfox
ip:port151.247.193.128:7777DarkCometthreatfox
ip:port189.150.133.139:1604DarkCometthreatfox
ip:port86.109.75.132:1604DarkCometthreatfox
ip:port82.102.219.33:1177NjRATthreatfox
ip:port188.212.158.102:1177NjRATthreatfox
ip:port188.48.226.49:1177NjRATthreatfox
ip:port103.233.194.35:1177NjRATthreatfox
sha1_hashd0b31bfd1d8e40efc3b3b30c1cf9b655c9365935NjRATthreatfox
sha256_hash03d2e8ef968a70c032ffb01c98b29ab612ae48043b44e63d15c2504f7f85de13NjRATthreatfox
md5_hash0f74892809973a93321c7ba05bdf61caNjRATthreatfox

+82 indicators in total. See them all on the IOCs page.

Transparent Tribe uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →