APT36
Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s)
About APT36
Android spyware of Transparent Tribe (APT36, "ProjectM" / "C-Major"), a Pakistan-nexus APT running South-Asia campaigns (documented by Kaspersky, Aug 2020). Simple, non-sophisticated implants with a recognizable manifest fingerprint: a `.MainS` service plus `.MyReceive` and `.CallReceive` receivers. The live C2 is not hardcoded - IOSocket carries a base64 const-string decoding to an online config URL (e.g. tryanotherhorse.com/config.txt) whose body the Config class parses for "Server IP" / "Domain Addr" at runtime.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| tryanotherhorse.com/config.txt | domain | 0c5b37b48769… | 2020-05-02 |
| tryanotherhorse.com/config.txt | domain | 52d1cb75b782… | 2020-01-03 |