APT36 Spear-Phishing on Indian Defence Bodies — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: Critical | View Full Scam Details

🛡️ Want to check if you've received this scam?

Check This Scam on BharatSecure →

APT36 Spear-Phishing Scam Targeting Indian Defence Bodies in 2026: What You Must Know

A critical cyber threat evolving in 2026: sophisticated spear-phishing attacks exploit digital trust to target Indian defence personnel.

What Is the APT36 Spear-Phishing on Indian Defence Bodies?

The APT36 spear-phishing scam is a highly targeted cyber attack campaign that focuses on Indian defence organizations and government bodies. According to public reports and security experts, these attacks originate from a Pakistan-linked group known as Transparent Tribe, which is alleged to use advanced social engineering techniques to infiltrate sensitive military and administrative networks. While the full impact is difficult to quantify due to the sensitive nature of the targets, Indian cybersecurity agencies have flagged a rise in such incidents over recent years, emphasizing their critical threat level.

This scam specifically targets officers and officials holding key roles within defence establishments by exploiting their trust in official communication channels such as email and official-looking websites. Using platforms like LinkedIn to gather personal and professional data, fraudsters craft convincing emails that appear to come from trusted government domains ending with “.nic.in” or “.gov.in.” This fake correspondence can include requests for verification of identity documents, purported updates to KYC information, or urgent operational instructions, increasing the likelihood that victims comply without suspicion.

India's CERT-In and the Ministry of Defence have acknowledged APT36-like spear-phishing campaigns as part of the broader threat landscape, highlighting the importance of vigilance and secure communication protocols in government and defence workplaces. In 2025 and 2026, proactive advisories have urged defence bodies to revise their cybersecurity training and incident response approaches.

How This Scam Works — Step by Step

  1. Target Identification: Attackers research individuals within the Indian defence network using LinkedIn and other social media to find names, job titles, email formats, and colleagues.

  2. Crafting the Email: The scammer creates a fake email domain mimicking official government domains. The email is meticulously designed to resemble genuine messages, sometimes including official logos and signatures.

  3. Sending the Spear-Phishing Email: The target receives an email requesting urgent KYC updates, Aadhaar verification, or compliance with new security protocols. Often, the email instructs the victim to download an attached document or click a link that leads to a malicious site.

  4. Credential Harvesting: When the victim follows the link or opens the attachment, they are prompted to enter sensitive personal information, such as Aadhaar details, login credentials, or mobile numbers.

  5. Account Compromise: With stolen credentials, fraudsters may gain unauthorized access to internal networks or personal devices. This breach can lead to data theft or manipulation.

  6. Secondary Attacks: Sometimes, the attackers follow up by attempting SIM swap frauds using the victim’s mobile number, which could give them access to OTPs (one-time passwords) for UPI payments or bank accounts.

  7. Monetary Loss & Data Leak: Stolen information might be used to perform illegal money transfers via UPI or internet banking, or to leak confidential defence-related information.

Real Warning Signs to Watch For

What Happens to Victims

Victims of this spear-phishing scam often suffer serious financial and emotional consequences. Financially, access to personal mobile numbers and Aadhaar data can facilitate fraudulent UPI payments or bank transfers which are difficult to reverse once completed. Unlike regular UPI transactions, those involving SIM-swapped numbers or compromised credentials complicate RBI’s reversal framework, leaving victims out of pocket.

Emotionally, defence personnel and government employees find their trust violated, leading to stress and reputational harm within their professional circles. In extreme cases, leaked defence information can impact national security, amplifying the seriousness of each individual data breach.

What RBI and CERT-In Say

The Reserve Bank of India (RBI) has reiterated through its cybersecurity advisories the need for vigilance against phishing attacks, emphasizing that sensitive information like OTPs and confidential details must never be shared over phone or email.

CERT-In, India’s national cybersecurity agency, continually alerts government entities about targeted spear-phishing attempts and encourages multi-factor authentication (MFA) and secure communication policies for official correspondence. The Ministry of Home Affairs’ Indian Cyber Crime Coordination Centre (I4C) also operates a 24x7 cybercrime helpline at 1930, urging victims to report cyber incidents promptly.

How to Protect Yourself

  1. Always verify the sender’s email address carefully—look for subtle differences from official government domains.
  2. Do not click links or download attachments without confirming their source, especially those requesting Aadhaar or KYC details.
  3. Avoid sharing OTPs, bank credentials, or Aadhaar information over email or phone calls.
  4. Use Multi-Factor Authentication (MFA) on all official and personal accounts.
  5. Regularly update passwords and avoid using the same password across multiple platforms.
  6. Report suspicious emails to your organization's IT security team immediately.
  7. Stay updated on official advisories from CERT-In, RBI, and the Ministry of Defence.

What to Do If You've Been Targeted

If you suspect you have been targeted by this scam, take these steps immediately:

Frequently Asked Questions

Q: Can this spear-phishing scam lead to financial theft even if I do not perform any transaction?
A: Yes. Fraudsters may use stolen Aadhaar or mobile details to initiate a SIM swap or access confidential accounts, which can bypass password protections and result in unauthorized transfers.

Q: How can I confirm whether an email from a government body is genuine?
A: Always check the email domain carefully (official government emails end with “.gov.in” or “.nic.in”). Do not trust emails that request personal information via links or attachments. When in doubt, verify through official phone numbers or IT teams.

Q: What measures does the government take against such spear-phishing attacks?
A: Bodies like CERT-In and the Ministry of Defence provide cybersecurity training, implement strict email filters, conduct internal audits, and encourage reporting through channels like the 1930 helpline to identify and mitigate these threats.

To safeguard yourself, always verify suspicious messages on BharatSecure.app and report fraud immediately to the cybercrime helpline at 1930.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.