Transparent Tribe is a Pakistan-associated cyber espionage threat actor widely tracked as APT36 and also known as ProjectM, Mythic Leopard, Earth Karkaddan, Operation C-Major, and in some reporting as Storm-0156 or Copper Fieldstone. The group has been active since at least the mid-2010s and is primarily focused on intelligence collection against Indian interests, especially government, military, diplomatic, defense-industrial, and more recently education-sector targets. Reporting also links related activity to targeting in Pakistan and Afghanistan, particularly where military, political, or government personnel are involved. Transparent Tribe is best known for sustained spearphishing and social-engineering operations using highly localized lures, including military, diplomatic, recruitment, and education themes. The actor commonly relies on weaponized documents, malicious shortcut files, archives, and trojanized applications to induce user execution. It has also operated malicious or spoofed websites, staged payloads on actor-controlled infrastructure and legitimate cloud services, and abused trusted platforms to blend command-and-control and delivery traffic with normal activity. The group has repeatedly deployed Windows and Android malware for espionage. Malware and toolsets publicly associated with Transparent Tribe include Crimson RAT, CapraRAT, and newer Google Sheets-based implants such as SheetAgent and SHEETCREEP. Crimson RAT has evolved over time from a relatively straightforward .NET remote access trojan into more capable variants with expanded command sets, anti-analysis logic, obfuscation, and support for additional components such as removable-media propagation. CapraRAT represents the actor’s long-running Android surveillance capability and has been embedded in trojanized messaging, dating, entertainment, and video-themed applications distributed outside official app stores. These mobile implants have supported collection of messages, contacts, call logs, files, screenshots, audio, camera data, and location information, while preserving enough benign functionality to maintain the lure. Transparent Tribe’s tradecraft consistently emphasizes persistence, surveillance, and evasion rather than technical novelty alone. Observed techniques include scheduled-task and startup-based persistence, hidden files and directories, masquerading with Windows-like names, anti-VM and anti-sandbox checks, security software discovery, system information discovery, and use of legitimate remote-management software for access and control. In multiple campaigns, the actor has abused cloud services such as Google Sheets and Google Drive as backup or primary command-and-control channels, enabling low-friction tasking and exfiltration over legitimate web infrastructure. Android operations have similarly shown iterative development to maintain compatibility across newer platform versions while retaining broad spyware functionality. Targeting patterns strongly indicate a strategic focus aligned with Pakistan’s regional intelligence priorities. Transparent Tribe has repeatedly targeted Indian diplomatic and military personnel, defense organizations, government entities, and strategic sectors, and has expanded into Indian educational institutions and students through themed lures. Some reporting also describes overlap with campaigns against Afghan government entities and finance-sector personnel through the SideCopy cluster. SideCopy is frequently described as a related cluster or subgroup operating under the broader Transparent Tribe umbrella, though some vendors track it separately. SideCopy has used similar South Asia-focused lures and malware delivery chains, including loader-based infections and customized open-source RATs, and has been linked to campaigns against Indian and Afghan government targets. Transparent Tribe has also been associated with infrastructure overlap, recurring lure themes, and repeated use of commodity and custom RAT ecosystems across campaigns. Overall, Transparent Tribe is a persistent, regionally focused espionage actor whose operations combine tailored social engineering, iterative malware development, abuse of legitimate services, and broad cross-platform surveillance capabilities in support of long-term intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.