The research highlights a change in strategy of the APT36 group, which expands its range of action from government institutions to startups active in the OSINT and cybersecurity sectors
Acronis, global leader in the cybersecurity and in the data protection announces that the Acronis Threat Research Unit (TRU) has identified a new cyber espionage campaign attributed with a high degree of certainty to the group known as the Transparent Tribe (APT36), active for over a decade and historically focused on government and military targets in South Asia. The analysis reveals a significant evolution in the profile of victims, with an extension of activities towards the Indian startup ecosystem, in particular companies operating in the cybersecurity and open-source intelligence (OSINT) sectors.
According to TRU researchers, the campaign uses social engineering techniques based on thematic content related to the startup world, distributed via ISO files and malicious LNK links, to convey Crimson RAT, a remote access malware already known and widely used by the group in previous espionage operations. The bait material analyzed refers to real content and figures actually present in the Indian technological ecosystem, with the aim of increasing the credibility of the attack and encouraging the execution of the payload by the victims.
The analysis conducted by TRU indicates that, while expanding its scope, the campaign remains consistent with Transparent Tribe's historical interest in cyber espionage activities linked to government, security and law enforcement areas. The targeted startups would in fact be involved, directly or indirectly, in projects to support public bodies and law enforcement agencies, making them strategic objectives for intelligence operations.
"This campaign confirms how even realities perceived as dynamic and innovative, such as startups active in the technological and cybersecurity fields, can become targets of cyber espionage operations. Collaborations with public bodies and institutions make it increasingly important to consider IT security and operational continuity as structural elements, not accessories", is the comment of Jozsef Gegeny, Security Researcher at Acronis TRU.
Crimson RAT, the malware used in the campaign, is designed for advanced surveillance activities and enables remote control of compromised systems, collection of system information, recording of audio and video, as well as data exfiltration. The research also highlights the reuse of infrastructures and operational methods already observed in previous campaigns attributed to the same group, to support the attribution of the analyzed activity.
The activity was detected and blocked by Acronis EDR and
The full report, “New Year, New Sector: Transparent Tribe Targets India’s Startup Ecosystem”, is available on the Acronis Threat Research Unit blog and includes detailed technical analysis of the campaign, elements to support attribution and indicators of compromise useful to security teams.






