Threats Tagged 'india'
View all threats tagged with 'india'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'india'
Click on any threat for detailed analysis and mitigation recommendations
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e... Join the discussion | AlienVault OTX General | 09/06/2026, 07:32:55 UTC Added: 09/07/2026, 10:22:27 UTC |
ValleyRAT is a backdoor malware distributed disguised as legitimate Chinese adware called QN Wallpaper. It uses DLL sideloading to execute malicious code under a signed process. The malware includes capabilities such as keylogging, clipboard monitoring, screenshot capture, and module delivery. The campaign has impacted over 1,500 users mainly in China and India with over 100,000 detections in 2026. The Silver Fox threat group is attributed to this campaign. The malware disables Windows Defender, establishes persistence, and protects its processes by marking them critical to cause system crashes if terminated. Join the discussion | AlienVault OTX General | 08/31/2026, 11:11:49 UTC Added: 08/31/2026, 15:38:07 UTC |
A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates. Join the discussion | AlienVault OTX General | 07/30/2026, 10:18:37 UTC Added: 07/31/2026, 11:22:21 UTC |
Mustang Panda orchestrated two concurrent espionage campaigns targeting Indian government entities and hydropower infrastructure between May and June 2026. The campaigns leveraged DLL sideloading via legitimate executables to deploy newly identified malware including SHARDLOADER, MINIRECON, and ZOHOMURK. MINIRECON represents an evolution of Toneshell with WebSocket-based command-and-control capabilities, while ZOHOMURK abuses Zoho WorkDrive cloud services for C2 communications and data exfiltration. Distribution occurred through spear-phishing with lures themed around India-Taiwan cooperation agreements and hydropower projects. The activity demonstrates code overlaps with previous tooling, infrastructure proximity to known operations, and targeting patterns aligned with Chinese strategic intelligence collection priorities. Multiple compromised government systems were identified, with coordination conducted through CERT-In for victim notification and remediation. Join the discussion | AlienVault OTX General | 06/29/2026, 20:25:13 UTC Added: 06/30/2026, 14:06:41 UTC |
Transparent Tribe, also known as APT36, has expanded its targeting to include India's startup ecosystem, particularly those in the cybersecurity domain. The group is using startup-oriented themed lure material delivered via ISO container-based files to deploy Crimson RAT. This campaign deviates from their typical government and defense targets, suggesting a shift in strategy towards companies providing open-source intelligence services and collaborating with law enforcement agencies. The attack chain involves spear-phishing emails, malicious LNK files, and batch scripts to execute the Crimson RAT payload. The malware employs extensive obfuscation techniques and uses a custom TCP protocol for command and control communications. This activity demonstrates the group's adaptation of proven tooling for new victim profiles while maintaining its core behavioral tactics, techniques, and procedures. Join the discussion | AlienVault OTX General | 02/04/2026, 15:57:21 UTC Added: 02/04/2026, 21:00:08 UTC |
A new campaign targeting Indian government entities was uncovered, utilizing three backdoors: SHEETCREEP, FIREPOWER, and MAILCREEP. These tools leverage legitimate cloud services like Google Sheets, Firebase, and Microsoft Graph API for command and control, enabling the attackers to blend in with normal traffic. The campaign, named Sheet Attack, employed PDFs and malicious LNK files as initial infection vectors. Evidence suggests the use of generative AI in malware development. While sharing similarities with APT36, the campaign's unique characteristics point to either a new Pakistan-linked group or an APT36 subgroup. The attackers demonstrated hands-on-keyboard activity and deployed additional payloads, including a document stealer, to selected targets. Join the discussion | AlienVault OTX General | 01/28/2026, 17:06:45 UTC Added: 01/28/2026, 19:05:05 UTC |
A Pakistan-linked APT group conducted two campaigns targeting Indian government entities. The Gopher Strike campaign used PDFs with malicious links to deliver an ISO file containing GOGITTER, a Golang downloader that fetches payloads from private GitHub repositories. GITSHELLPAD, a Golang backdoor, was used for C2 communication via GitHub. GOSHELL, a Golang shellcode loader, deployed Cobalt Strike Beacon on specific hostnames. The attackers used various techniques including scheduled tasks for persistence, obfuscation, and environmental keying. Post-compromise activities involved system reconnaissance and data exfiltration. The campaign demonstrated sophisticated TTPs and custom-built tools, indicating a potentially new subgroup or parallel Pakistan-linked threat actor. Join the discussion | AlienVault OTX General | 01/26/2026, 21:19:21 UTC Added: 01/27/2026, 07:35:56 UTC |
A sophisticated campaign by the Chinese APT group Silver Fox is targeting Indian entities with authentic-looking Income Tax phishing lures. The attack leverages a complex kill chain involving DLL hijacking and the modular Valley RAT to ensure persistence. The campaign uses a multi-stage infection process, starting with a malicious email containing a PDF decoy. The payload is delivered through an NSIS installer, which drops a legitimate Thunder.exe binary and a malicious libexpat.dll for DLL hijacking. The final stage involves the Valley RAT, which uses a two-stage configuration loading mechanism and implements a 3-tier C2 communication loop. The RAT's modular plugin architecture allows for dynamic capability extension and persistence through registry-based storage. Join the discussion | AlienVault OTX General | 12/24/2025, 21:10:40 UTC Added: 12/26/2025, 10:02:55 UTC |
A sophisticated phishing campaign impersonating the Indian Income Tax Department has been targeting local businesses. The attack begins with a spear-phishing email containing a PDF attachment that directs victims to a fake compliance portal. This triggers the download of a malicious ZIP file, which initiates a multi-stage infection chain. The payload, delivered through NSIS installers, deploys a Remote Access Trojan (RAT) with persistence capabilities. The malware harvests system information and establishes communication with command and control servers. Technical indicators suggest a China-linked development environment. This campaign demonstrates how seemingly simple tax-themed phishing can lead to complete device compromise, emphasizing the need for heightened security awareness. Join the discussion | AlienVault OTX General | 12/22/2025, 17:06:59 UTC Added: 12/23/2025, 09:21:49 UTC |
A sophisticated espionage campaign targeting Indian entities has been identified, masquerading as the Income Tax Department of India. The activity is associated with the SideWinder APT group, which has evolved its toolkit to evade detection by mimicking Chinese enterprise software. The campaign uses DLL side-loading techniques with legitimate Microsoft Defender binaries to bypass EDR, and utilizes public cloud storage and URL shorteners to evade reputation-based detections. The threat actors employ geofencing behavior, focusing on systems in South Asian timezones. The attack chain includes phishing emails, fraudulent websites, and malicious payloads delivered through file-sharing services. The final stage involves a resident agent that beacons to a command-and-control server, mimicking Chinese endpoint tool protocols. Join the discussion | AlienVault OTX General | 12/20/2025, 17:19:05 UTC Added: 12/22/2025, 10:37:54 UTC |
Showing 1 to 10 of 17 results