APT36 Spear-Phishing on Indian Defence Bodies
INDIA — By BharatSecure Threat Intelligence Team ·
Verdict Summary
APT36 Spear-Phishing on Indian Defence Bodies shows strong scam indicators common in fraud targeting Indian users. Do not share OTPs, passwords, or payments — verify the source independently.
Risk score: 9/10 · Severity: Critical · Verdict: Suspicious
Scam Intelligence: APT36 Spear-Phishing on Indian Defence Bodies
Proprietary signals from BharatSecure's scam-tracking database.
| Last reported | May 02, 2026 |
How APT36 Spear-Phishing on Indian Defence Bodies Works
Overview: APT36 spear-phishing scams are malicious cyberattacks specifically targeting Indian governmental and defence personnel, including members of the armed forces, public sector undertakings, and senior officials in ministries. Orchestrated by the Pakistan-linked group Transparent Tribe, these campaigns are dangerous as they seek confidential national security information via deceptive emails and malware, risking operational integrity and personal data. How It Works: Attackers create emails appearing to be from legitimate Indian government address[ADDRESS_REDACTED].nic.in.ministryofdefenceindia.org instead of the authentic .nic.in). Leveraging newsworthy events like terror attacks or urgent defence alerts, they prompt users to open attachments or click links. Upon interaction, malware such as Crimson RAT is silently installed on the device, enabling remote access, keystroke logging, and data theft. Through this, attackers gain persistent control to execute commands, exfiltrate files, and spy on sensitive information. India Angle: This scam focuses largely on central and state government entities and particularly targets North Indian regions with dense defence infrastructure. Phishing emails exploit platforms like official government email, internal communication portals, and sometimes messaging apps for distribution. Many victims are senior employees in ministries, defence services, and contractors using Aadhaar or other personal identification for access. Real Examples: - "As directed by Ministry of Defence, please download this urgent security update regarding the Pahalgam incident (attachment)." - "IAF: All officers must verify credentials after new alert. Visit [malicious-link]." - "Official order regarding increased threat levels attached; urgent response needed." Red Flags: - Email address[ADDRESS_REDACTED]. - Messages referencing very recent terror events to evoke urgency. - Attachments or links whose URLs closely resemble but are not identical to real government sites. - Direct request to download files or enter passwords onto unfamiliar forms. - Instructions to bypass standard IT protocols for immediate action. Protective Measures: - Always confirm sender identity for urgent emails through a separate official channel. - Use robust, up-to-date anti-malware and enable multi-factor authentication (MFA) wherever possible. - Never open attachments from unfamiliar government-related emails. - Regularly conduct cybersecurity awareness training per CERT-In guidelines. - Encourage semi-annual ICT and security audits for all government personnel. If Victimised: - Immediately disconnect the affected device from the internet. - Report the cyber incident to the RBI helpline 1930 and file details at cybercrime.gov.in. - Inform your IT/cybersecurity team and CERT-In as soon as possible to limit potential breaches. Related Scams: - Credential harvesting through fake government portals. - Malware infections via pirated software claiming to be defence utilities. - Social engineering attacks targeting Aadhaar/KYC verification in government offices.
How This Scam Works — Detailed Explanation
APT36 spear-phishing scams primarily target Indian defence bodies by exploiting digital communication platforms, notably email. The attackers, linked to the Pakistan-based group Transparent Tribe, meticulously research their targets, identifying individuals in critical roles within the military and government sectors. They often use social media platforms such as LinkedIn to gather personal information about potential victims, allowing them to craft highly convincing emails that appear legitimate. For instance, they might create a fake email domain that closely resembles an official .nic.in or .gov.in address. This attention to detail is crucial in deceiving recipients who are conditioned to trust communications from their own government.
The psychological tactics involved in APT36’s strategy are calculated and manipulative. The group often employs urgency and pressure to compel immediate action from the victims. Emails frequently reference ongoing national security issues, prompting an emotional reaction that undermines the recipient’s critical thinking. Victims may receive an email claiming to be from a senior official asking them to provide sensitive information or excel files that they must open immediately to address “urgent matters.” Such messages can prompt even the most cautious individuals to act without thoroughly reviewing the sender’s authenticity. The combination of urgency and a fear of repercussions is a potent psychological weapon for attackers.
Once victims engage with the phishing email, the consequences can unfold rapidly. After clicking on an attached file or link, they may unknowingly install malware that grants the attackers access to their devices and sensitive information. Take, for example, a case involving a defence researcher whose Aadhaar details were captured through a malicious link disguised as an official government portal. The attacker used the information to initiate unauthorized transactions, leading to significant financial loss. Many victims may find their private information dumped onto the dark web, where cybercriminals exploit it for financial gain. The experience can cause panic as they attempt to mitigate damage while navigating through steps to secure their personal data.
The impact of APT36 spear-phishing operations on Indian national security and individual victims is significant. In recent years, Indian cybercrimes attributed to such groups have led to losses exceeding ₹300 crore, with numerous reports filed through the Ministry of Home Affairs (MHA) and RBI guidelines on cybersecurity. The RBI and CERT-In have issued advisories underscoring the critical nature of these threats. Victims not only face financial repercussions but endure emotional distress from the vulnerability of their personal information. Government entities must remain vigilant as these attacks not only compromise individual security but have the potential to threaten national stability.
To effectively distinguish between APT36 spear-phishing scams and legitimate communications, individuals must look for specific telltale signs. Be wary of emails from sender addresses that slightly alter official domains, as attackers are skilled at creating imitations that are hard to discern from the original. Legitimate emails from defence or government officials do not typically request immediate actions or gather sensitive information via unsecured emails. Moreover, always examine any hyperlinks closely; avoid clicking links with unusual extensions or those that lead to unfamiliar web pages. Establishing a protocol for double-checking such requests via direct phone calls can significantly reduce the risk of falling victim to these sophisticated scams.
Visual Intelligence:
BharatSecure's AI has identified this as a used in scams targeting Indian users.
Who Does APT36 Spear-Phishing on Indian Defence Bodies Target?
General public across India
Red Flags — How to Identify APT36 Spear-Phishing on Indian Defence Bodies
- Sender’s email domain looks almost but not exactly like a real .nic.in or .gov.in address
- Urgent emails referencing ongoing national security incidents
- Unexpected attachments or requests for credential input
- Requests to bypass normal cybersecurity procedures
- Links with elongated or odd-looking domains mimicking official portals
What To Do If You Encounter APT36 Spear-Phishing on Indian Defence Bodies
- Report suspicious emails to cybercrime.gov.in or call the cybercrime helpline at 1930 immediately.
- Do not open unverified email attachments or click on any suspicious links.
- Verify sender details by contacting the individual or organization through known official channels.
- Change your passwords across accounts if you suspect you've fallen for a phishing attempt.
- Keep your software and antivirus programs updated to protect against malware infections.
- Educate colleagues in your organization about recognizing phishing scams and maintaining cybersecurity hygiene.
How to Report APT36 Spear-Phishing on Indian Defence Bodies in India
- Call 1930 — National Cyber Crime Helpline (24x7)
- File a complaint at cybercrime.gov.in
- Contact your bank immediately if money was lost
- Call RBI helpline: 14440 for banking fraud
Frequently Asked Questions
- What to do if I clicked on a suspicious email link related to a KYC scam?
- Immediately disconnect your device from the internet and run a full antivirus scan. Contact your bank's helpline, like SBI at 1800-11-1109, to alert them about the incident.
- How can I identify an APT36 spear-phishing email?
- Look for telltale signs such as slightly altered email addresses, requests for urgent action, and unexpected attachments. If something feels off, always verify directly with the supposed sender.
- How do I report this type of scam in India?
- You can report these scams at cybercrime.gov.in or contact the cybercrime helpline at 1930. Additionally, notify your bank immediately using their fraud helpline.
- Can I recover my money if I've been scammed?
- If money was lost due to a scam, contact your bank right away using their customer helpline. They may assist in investigating the transactions and potentially recovering funds. Always report the incident to law enforcement as well.
How This Scam Works — BharatSecure AI
Spreading fastA plain-language breakdown based on 40 real reported scams of this type.
| How they reach you | Reported primary vectors are unsolicited WhatsApp messages, SMS/smishing, and direct phone/WhatsApp calls impersonating banks, UPI providers, telecom, or government agencies, often containing phishing |
| How they gain your trust | Fraudsters establish credibility by impersonating trusted authorities (banks, RBI, UIDAI, police, HR recruiters, or scheme agents) and referencing legitimate regulatory processes like mandatory KYC up |
| How they take your money | Documented rails include UPI apps and digital wallets (Paytm, PhonePe, SBI YONO), direct bank credential/OTP harvesting for unauthorized transfers, an |
| Who they target | Most commonly targeted are the elderly, homemakers, rural and first-time/Jan Dhan bank users, students and job seekers, small businesses and vendors, and urban professionals; they are chosen for lower |
- authority bias (impersonating banks/government/police)
- urgency and scarcity (imminent account freeze/deactivation)
- fear and loss aversion (threats of digital arrest, penalties, or blocked funds)
- Unsolicited urgent KYC/Aadhaar/PAN update requests threatening account suspension, deactivation, or 'digital arrest'
- Links to non-official domains (.xyz, .in lookalikes) instead of RBI-mandated .bank.in or official government portals
- Requests to install remote-access/screen-sharing apps like AnyDesk or TeamViewer for 'verification'
- Requests to share OTPs, PINs, CVV, Aadhaar, PAN, or selfies/video for KYC
- Demands for advance fees, unusual payment channels (Bitcoin ATM deposits), or fake video KYC calls captured via manipulated feeds
Related Scams in India
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.