Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pakistan-linked APT36, also known as Transparent Tribe, was reported targeting Indian government and defense entities in an August 2025 campaign that used meeting-themed phishing and Linux .desktop files as malware loaders. The activity fits a longer pattern of suspected espionage targeting Indian institutions, but public reporting does not establish that every cyberattack reported during the 2025 India-Pakistan crisis came from APT36.

Who are the hackers behind the reported campaign?

The actor named in SecurityWeek’s 25 August 2025 report is APT36, also known as Transparent Tribe. MITRE ATT&CK lists the group as G0134 and records the aliases COPPER FIELDSTONE, Mythic Leopard, and ProjectM. MITRE describes it as a suspected Pakistan-based group active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.

“Pakistan-linked” or “suspected Pakistan-based” is the appropriate qualification: these are public threat-intelligence assessments, not a court finding. RUSI characterizes Transparent Tribe as a persistent threat to Indian government and defense-affiliated entities, with an espionage interest in information relevant to Pakistani military and diplomatic concerns.

How did the Linux phishing campaign work?

  1. Use a plausible meeting lure. The August 2025 campaign used phishing emails framed as meeting notices to persuade recipients to interact with delivered material.
  2. Abuse a Linux desktop entry. The emails involved Linux .desktop files, a desktop-entry format that can launch an application or command. In this campaign, SecurityWeek described the files as loaders: if a recipient treated one as a legitimate meeting-related file and launched it, it could help start the malware delivery process.
  3. Use Google Drive in the attack lifecycle. SecurityWeek quoted CloudSEK saying the group’s use of Google Drive represented an evolution in its approach. The public account does not specify enough to establish Google Drive’s exact role at each stage, or to reconstruct a complete command-and-control chain.

This is a social-engineering and execution risk, not evidence that Linux itself was exploited or that all Linux systems automatically run a downloaded .desktop file. The reported adaptation is notable because the lure and loader were suited to the target’s Linux environment; it does not establish that APT36 has stopped targeting other operating systems.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Lenovo Business Laptop - Linux Mint (Cinnamon) - Intel i5-1335U, 16GB RAM, 256GB SSD, 15.6" FHD 1920x1080 Display, Full Keyboard, Fast Charging
  • Intel Core i5-1335U Processor (12M Cache, 12 Threads, up to 4.6 GHz) - 256GB Solid State Drive - 16GB DDR4 SDRAM
  • 15.6" FHD (1920x1080) Non-Touch Anti-Glare Display - Intel UHD 620 Integrated Graphics - Stereo Speakers
  • 720p HD Webcam with Privacy Shutter. Integrated Microphone - Intel Dual Band Wireless-AC (2x2) 8265, Bluetooth Version 4.2
  • I/O Ports: 2x USB 3.0, 1x USB 3.1 Type-C 3.1, Headphone/Mic Combo Port, 4-in-1 Card Reader, HDMI, Kensington Mini-Lock Slot
  • Linux Mint (Cinnamon) 64-Bit - Keyboard with Full NumberPad - Fast Charging

What organizations and users should do

The campaign’s reported entry point makes handling unexpected meeting files a practical priority. Linux organizations should treat desktop-entry files received by email or shared links as executable content, not as ordinary documents.

  • Confirm unexpected meeting notices with the purported sender through a known channel before opening or launching attachments.
  • Do not launch an unfamiliar .desktop file to preview its contents. If it needs investigation, route it to the organization’s security team.
  • Use endpoint controls and monitoring to review unexpected launches from user-writable locations, especially when followed by unusual script, network, or file activity.
  • Review access to cloud-storage services in context rather than assuming a familiar service makes a file trustworthy. Google Drive’s presence in an attack path does not, by itself, prove a file is malicious.
  • If a file was launched unexpectedly, report it promptly and preserve the message and relevant endpoint records for incident response.

How this activity fits the wider India-Pakistan cyber context

The August campaign came amid heightened cyber activity following the Pahalgam attack and Operation Sindoor in May 2025. RUSI and Indian policy reporting described a wider mix of phishing, fake domains, malware delivery, denial-of-service activity, and information operations. That context matters, but it should not be conflated with attribution of the specific Linux campaign: the August report identifies APT36, while the broader activity involved multiple actors and techniques.

Rank #2
HP 17 Business Laptop - Linux Mint Cinnamon - Intel Quad-Core i5-10210U, 32GB RAM, 1TB PCIe NVMe SSD + 1TB Storage HDD, 17.3" Inch HD+ (1600x900) Display
  • Intel Core i5-10210U (up to 4.2GHz) - 1TB PCIe NVMe + 1TB HDD - 32GB DDR4 SDRAM
  • 17.3" HD+ (1600x900) Display, Intel UHD Graphics 620
  • Built in HD 720p Webcam with Microphone - Bluetooth Version4.2
  • I/O Ports: 2x USB 3.1 (Data Only), 1x USB 2.0, 1x HDMI, 1x Headphone/Microphone Combo Jack
  • Linux Mint Cinnamon 64-Bit - 6-Row Keyboard w/ Full Numberpad

Reported attack totals also refer to separate assessments, not a single standardized or independently audited count. RUSI relayed a Maharashtra Cyber assessment of more than 1.5 million cyberattacks after the Pahalgam attack. ICWA separately reported Maharashtra Cyber’s assessment that seven APT groups were behind more than 15 lakh attacks on critical-infrastructure websites, with 150 described as successful. Those figures have different descriptions and are attributed to Maharashtra Cyber through the respective publications; they do not show that APT36 was responsible for all, or any particular share, of the totals.

Timeline of reported activity

Date What was reported What it establishes
Since at least 2013 MITRE ATT&CK records Transparent Tribe activity targeting diplomatic, defense, and research organizations in India and Afghanistan. A long-running targeting pattern, not proof that every later incident is attributable to the group.
27 May 2024 A DRDO-hosted news digest summarized reporting that Transparent Tribe targeted Indian defense-establishment employees and firms connected to the Department of Defence Production. Prior reporting on defense-related targets; it is distinct from the 2025 Linux campaign.
May–June 2025 RUSI and Indian policy sources described cyber operations occurring alongside the crisis after Pahalgam and Operation Sindoor, including fake domains, malware, and DDoS activity. A broader period of reported operations involving more than the APT36 campaign.
August 2025 SecurityWeek reported APT36’s meeting-themed phishing and Linux .desktop-file campaign against Indian government entities. The specific campaign at the center of this article.
15 September 2025 India Today described an “OP Sindoor Lessons For Action” PDF lure aimed at Linux systems used by government agencies and linked the technique to APT36. A later report of a related Linux-focused lure; it does not, by itself, prove that the same infrastructure or operation was involved.
January 2026 CSIS recorded another Pakistan-aligned APT36 campaign targeting Indian government, academic, and strategic institutions for data exfiltration and persistent surveillance. Public reporting continued to describe APT36 activity after the August 2025 incident.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known—and what remains unproven

The public reporting supports a clear account of the campaign’s broad approach: meeting-themed phishing, Linux desktop-entry files used as loaders, and Google Drive somewhere in the attack lifecycle. It does not provide a complete technical chain, a verified victim count, or a standardized measure of success. The broader crisis-era attack totals should not be treated as APT36 statistics. As of the latest dated reporting covered here, CSIS’s January 2026 timeline indicates continued attribution of activity to APT36, but it does not establish the group’s current operational status beyond that report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Lenovo IdeaPad Slim 3 Linux Laptop, 15.6" FHD Touchscreen Laptop, 8-Core AMD Ryzen 7 5825U, 16GB RAM, 512GB SSD, Keypad, SD Card Reader, Stylus Pen + External Portable SSD + USB Hub, Linux Ubuntu OS
  • Powerful Linux Laptop: This IdeaPad Slim 3 Laptop comes pre-installed with Ubuntu Linux, offering fast performance, robust security, and a clean, user-friendly experience. Enjoy full customization, seamless hardware compatibility, and access to thousands of open-source apps. Whether you're working, creating, or coding, it's built to keep up with everything you do.
  • A Multitasking Master: The latest AMD Ryzen 7 5825U processor (up to 4.5 GHz) delivers powerful performance with 8 cores and 16 threads for smooth multitasking. Integrated AMD Radeon Graphics provide crisp visuals for streaming, browsing, photo editing, and casual gaming. With smart machine intelligence, it adapts to your needs for a fast, responsive experience.
  • 15.6" Full HD Display: The IdeaPad Slim 3 boasts an 88% screen-to-body ratio for a floating, edge-to-edge visual experience. TÜV Low Blue Light certification reduces eye strain, making it perfect for long work or study sessions.
  • Military-Grade Durability: The smart IdeaPad Slim 3 combines portability and durability, letting you work, study, and play on the go. With a profile 10% slimmer than the previous generation, it's lightweight yet military-grade rugged, ready for anything, anywhere.
  • Versatile Connectivity: Enjoy the security of a built-in webcam with a privacy shutter. Connect effortlessly with multiple ports: 2x USB A, 1x USB C, 1x HDMI, 1x SD Card Reader, 1x Headphone/Microphone combo. Bundle comes with Stylus Pen, 256GB Portable SSD and 5-in-1 Docking Station.
Rank #4
Sale
Lenovo V15 Gen 4 - Business Laptop - AMD Ryzen 5 7430U - 15.6" FHD Display - 8GB RAM - 512GB SSD Storage - Integrated AMD Radeon™ Graphics - Webcam Privacy Shutter - Business Black
  • THE POWER TO STAY PRODUCTIVE – Looking to make your everyday work and home life more manageable without breaking the bank? The Lenovo V15 Gen 4 offers long-term reliability with top-of-the-line features to make you your most productive self.
  • CRUSH YOUR TO-DO LIST – The AMD Ryzen CPU pairs quiet performance and enhanced operating power to crush your high-demand workday. It optimizes performance and allows for seamless multitasking.
  • TRUE-TO-LIFE VISUALS – The 15.6” FHD IPS display is anti-glare with 300 nits brightness to see your best outside or in. Its 88% screen-to-body ratio makes viewing detailed applications like spreadsheets a breeze.
  • SEAMLESS COLLABORATION – Lenovo Smart Appearance enhances your camera effects to protect your privacy and to make you the focus of every video conference. Intelligent noise cancelation minimizes distraction and Dolby Audio provides an elegantly sonorous experience.
  • BUILT TO WITHSTAND – Built for military-grade toughness, the V15 Gen 4 is tested to withstand harsh temperatures, pressure, humidity, vibrations and more. Keep your work safe from the board room to your living room and everywhere in between.
Rank #3
Panasonic Toughbook CF-31 MK5 Rugged Laptop, 13.1in i5, 8GB 256GB (Renewed)
  • [ULTRA-RUGGED DESIGN] MIL-STD-810G and IP65 certified. Built to survive 6-foot drops, heavy rain, and extreme vibrations. Features a magnesium alloy chassis with an integrated carry handle for maximum portability
  • [4G LTE - WORK ANYWHERE] Integrated 4G LTE Multi-Carrier Mobile Broadband. Stay connected to the internet in remote areas or on the road without relying on Wi-Fi or phone hotspots. True mobile freedom for field professionals
  • [1200-NIT SUNLIGHT READABLE] 13.1" XGA Touchscreen with CircuLumin technology. At 1200 nits, it is nearly 4x brighter than a standard laptop, ensuring perfect visibility under direct, intense sunlight
  • [LINUX UBUNTU PRE-INSTALLED] Fast, secure, and bloatware-free. Optimized for developers, network engineers, and diagnostic software that thrives in a stable, open-source environment
  • [LEGACY SERIAL PORT] Features a native RS-232 Serial Port, HDMI, and USB 3.0. Essential for connecting directly to industrial machinery, CNCs, and automotive diagnostic tools without unreliable adapter

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.