19.1 C
New York
September 18, 2025
NationNews
Tech News

Indian Government Systems Under Attack: Hackers Deploy Fake Shortcut Files

Indian Government Systems Under Attack: Hackers Deploy Fake Shortcut Files

Indian Government Systems Under Attack: Hackers Deploy Fake Shortcut Files
In a concerning turn of events, Indian government systems are facing renewed cyber threats as the notorious hacker group Transparent Tribe (APT36) leverages deceptive tactics to break into official networks. The group has deployed weaponized shortcut files that masquerade as legitimate PDF documents, targeting both Windows and BOSS (Bharat Operating System Solutions) Linux systems.
Attack Strategy and Execution
According to security firm CYFIRMA, the campaign begins with spear-phishing emails that appear to contain meeting notices. These emails carry seemingly innocuous files such as “Meeting_Ltr_ID1543ops.pdf.desktop”. Once opened, these files execute a shell script that:
Downloads a hex-encoded ELF binary from an attacker-controlled server (e.g., securestore[.]cv),
Executes the binary,
Opens a decoy PDF (often via Firefox) to mislead the user, while the real malware operates stealthily in the background
The malicious payload then communicates with a hardcoded command-and-control server (modgovindia[.]space:4000) to receive commands and exfiltrate data . Moreover, persistence is established via a cron job, ensuring the malware remains active even after reboot or termination The
Broader Impact and Technical Sophistication
APT36’s tactics extend beyond Linux. The group also targets Windows systems with tailored shortcut techniques, alongside deploying remote access tools and backdoors like Poseidon. These enable credential harvesting, data exfiltration, and long-term access across compromised environments
Additional surveillance by cybersecurity firms such as Hunt.io and CloudSEK highlights that the malware incorporates anti-debug and anti-sandbox mechanisms—designed to evade detection by automated security tools
Persistent Threat from APT36
Transparent Tribe, operational since at least 2013, is widely attributed to Pakistani origin and is known for its long history of cyber-espionage against Indian government institutions, especially in defense sectors GovInfoSecuritySecurity Week. The group’s evolving methods underscore a growing threat to national digital infrastructure.
What This Means for Indian Cybersecurity
The use of fake shortcut files underlines a critical vulnerability—social engineering remains a potent vector. As a countermeasure, security experts recommend:
Disabling auto-execution of desktop shortcuts and implementing application allow-lists on BOSS Linux images.
Enforcing read-only modes for documents and isolating downloads from untrusted networks.
Adopting zero-trust segmentation to limit lateral movement in compromised environments
Stay Informed
To remain updated with the latest developments in technology and cybersecurity, read more on our Technology page:
Visit the Latest Tech News

Related posts

🔥 Mega Deals on Security Cameras – Save Big on Top Brands!

Nation News Desk

कागज से पतला होगा मोबाइल, टूटने का डर भी खत्म, आईआईटी मंडी ने विकसित किया खास 2डी मटीरियल

Nation News Desk

आपदा में फेल हुआ डिजिटल इंडिया, सैटेलाइट फोन बना सहारा

Nation News Desk

Washington Takes Aim at AI: Bipartisan Senate Bill Proposes New Federal Agency to Regulate Big Tech

Nation News Desk

Vinfast Ignites India’s EV Market: VF6 & VF7 Electric SUVs Launched with Game-Changing Prices and 10-Year Warranty

Nation News Desk

Upgrade Your Home Cinema: Amazon Unleashes Massive Discounts on Sony, Samsung, and LG 4K Smart TVs

Nation News Desk

TVS Orbiter EV Launched at ₹99,900, Offering High-Tech Features at an Entry-Level Price

Nation News Desk

Top Tech Trends in the U.S. – September 2025Apple’s ‘Awe Dropping’ Event – iPhone 17…

Nation News Desk

The Unicycle Commuter: Bengaluru’s New Traffic Phenomenon

Nation News Desk

The Outer Worlds 2 wants you to join the space police

Nation News Desk

The Cupertino Conundrum: Apple’s Dance Between Refinement and Radical Innovation

Nation News Desk

Tesla vs Mahindra: How Brand Loyalty Shapes India’s EV Market”

Nation News Desk

Tesla Cybertruck officially launches in Korea

Nation News Desk

Tech News from the World of Google: AI Integration Deepens, Pixel 10 Impresses

Nation News Desk

TCS Announces Salary Hikes Amid Global IT Slowdown, But Increments Hit Four-Year Low

Nation News Desk

Tamron 28-300mm F/4-7.1 Di III VC VXD – The Ultimate Telephoto Lens for Sony Full-Frame Mirrorless Cameras

Nation News Desk

Smart Green Bridge in Alberta Dramatically Reduces Wildlife Collisions

Nation News Desk

Small Businesses Can Reach New Heights with ASUS Business Technology

Nation News Desk

Shop Directly from ASUS eSHOP and Get Exclusive Offers

Nation News Desk

Samsung Galaxy Event: Introducing the Galaxy AI Experience to Our Latest Innovations

Nation News Desk

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More

error: Content is protected !!