Adversary-emulation profile for APT36 (G0134 / Transparent Tribe / Mythic Leopard / ProjectM / COPPER FIELDSTONE), a Pakistan-linked cyber-espionage actor targeting Indian government, defense, and diplomatic entities.
54
61%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt36-transparent-tribe/SKILL.mdAPT36 (MITRE ATT&CK G0134) is a suspected Pakistan-based cyber-espionage group active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan. The group is believed to operate in alignment with Pakistan's Inter-Services Intelligence (ISI) strategic interests, conducting persistent intelligence collection against India's government, military, aerospace, and — more recently — educational and startup sectors. APT36 is characterized by heavy reliance on spearphishing with weaponized Office documents delivering its signature CrimsonRAT (.NET implant), Android mobile surveillance via CapraRAT, watering hole attacks, social engineering through honey traps and fake personas, and USB-based lateral movement — a pragmatic, high-volume approach tuned for the India-Pakistan geopolitical theater.
Asia/Karachi) timezone artifacts embedded in delivered payloads and server configurations.cmd.exe / COMSPEC.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| Crimson / CrimsonRAT | S0115 | .NET Windows RAT — flagship implant (keylogging, screen/video/audio capture, USB spreading, email collection) | Custom |
| ObliqueRAT | S0644 | Windows RAT with steganography delivery, USB data collection, sandbox evasion | Custom |
| Peppy | S0643 | Python-based Windows RAT — keylogging, screen capture, automated file exfiltration | Custom |
| CapraRAT | (no ATT&CK software ID) | Android RAT (modified AndroRAT) — SMS/call/contact theft, location tracking, audio recording; disguised as YouTube/messaging apps | Custom |
| ElizaRAT | (no ATT&CK software ID) | Windows RAT — CPL-initiated, Google Storage distribution, evolving C2 (Telegram/Slack/Google Drive) | Custom |
| Limepad | (no ATT&CK software ID) | Windows stealer companion to ElizaRAT | Custom |
| DarkComet | S0334 | Windows RAT with RDP, keylogging, video/audio capture | Public |
| njRAT | S0385 | Windows RAT with RDP, keylogging, USB spreading, browser credential theft | Public |
Note: CapraRAT, ElizaRAT, and Limepad are well-documented custom APT36 tools but do not yet have assigned MITRE ATT&CK software IDs. CrimsonRAT (S0115) is the group's signature implant used continuously since at least 2016.
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. Mobile (CapraRAT-style) emulation requires explicit mobile-device scope authorization.
Map APT36's signature plays to Decepticon's own capabilities:
mshta.exe. Register typo-squatted domains mimicking government file-sharing or education portals; stage payloads on attacker infrastructure with SSL certificates.mshta.exe chain with fileless in-memory payload loading.HKCU\Software\Microsoft\Windows\CurrentVersion\Run) and/or Startup folder — mirroring CrimsonRAT's documented persistence mechanism. Adapt persistence strategy based on detected AV product (APT36's 2025-2026 pattern).mshta.exe execution from email-sourced paths; user awareness training on government/defense-themed lure recognition.If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.