CYFIRMA Research: OSINT Investigation- Hunting Malicious Infrastructure Linked to Transparent Tribe
Manage episode 442943320 series 3472819
CYFIRMA's latest report delves into a crucial investigation targeting the malicious infrastructure linked to the APT group "Transparent Tribe." Employing open-source intelligence (OSINT), we thoroughly tracked the command-and-control (C2) servers utilized by this persistent threat actor. By leveraging advanced techniques such as JARM fingerprinting, we identified a network of 15 servers hosted by DigitalOcean, primarily aimed at malicious activities against individuals in India, reflecting the group's historical focus on Indian government sectors.
This investigation reveals the group's innovative use of Linux desktop entry files as attack vectors, highlighting their continuous adaptation in the dynamic cyber landscape. Additionally, the report details their evolving tactics, including the deployment of Mythic Poseidon binaries as malicious payloads, underscoring the sophistication of this threat.
Link to the Research Report: OSINT Investigation: Hunting Malicious Infrastructure Linked to Transparent Tribe - CYFIRMA
#CyberThreat #OSINT #TransparentTribe #APT36 #CyfirmaResearch #MaliciousInfrastructure #ExternalThreatLandscapeManagement #ETLM #CYFIRMA #CyfirmaResearch
https://www.cyfirma.com/
202 episodes