APT36

Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s)

About APT36

Android spyware of Transparent Tribe (APT36, "ProjectM" / "C-Major"), a Pakistan-nexus APT running South-Asia campaigns (documented by Kaspersky, Aug 2020). Simple, non-sophisticated implants with a recognizable manifest fingerprint: a `.MainS` service plus `.MyReceive` and `.CallReceive` receivers. The live C2 is not hardcoded - IOSocket carries a base64 const-string decoding to an online config URL (e.g. tryanotherhorse.com/config.txt) whose body the Config class parses for "Server IP" / "Domain Addr" at runtime.

Indicators

IndicatorTypeSampleFirst seen
tryanotherhorse.com/config.txt domain 0c5b37b48769… 2020-05-02
tryanotherhorse.com/config.txt domain 52d1cb75b782… 2020-01-03