comScore
Active Stocks
Mon Dec 04 2023 14:33:01
  1. Reliance Industries share price
  2. 2,420.75 1.14%
  1. Power Grid Corporation Of India share price
  2. 212.75 1.14%
  1. State Bank Of India share price
  2. 592.35 3.58%
  1. Tata Steel share price
  2. 131 0.81%
  1. HDFC Bank share price
  2. 1,603.7 3.1%
Business News/ Technology / News/  Pakistan-based threat actors attacking IITs, Indian Army: Modus operandi, motive, and other details to know
Back Back

Pakistan-based threat actors attacking IITs, Indian Army: Modus operandi, motive, and other details to know

Pakistan-based group Transparent Tribe has been conducting cyber attacks against the Indian Army and education sector. The group is believed to be attempting to obtain sensitive information via the malicious file ‘Revision of Officers posting policy’, which is disguised as a legitimate document.

The group is using a malicious file titled 'Revision of Officers posting policy' to lure the Indian Army into compromising their systems.Premium
The group is using a malicious file titled 'Revision of Officers posting policy' to lure the Indian Army into compromising their systems.

A new wave of cyber attacks against the Indian Army and the education sector organised by a Pakistan-based group has come to light. According to a report by Seqrite, the enterprise arm of Pune-based Quick Heal Technologies, the threat group is called Transparent Tribe. It has been targeting Indian military entities and educational institutions in the country, such as IITs and NITs. The group is believed to have originated in 2013. 

Aim of these attacks? The threat group targets to deceive unsuspecting victims into divulging sensitive information through this sophisticated tactic.

According to the researchers, the group is using a malicious file titled "Revision of Officers posting policy" to lure the Indian Army into compromising their systems. The file is disguised as a legitimate document, but it contains embedded malware designed to exploit vulnerabilities.

The cybersecurity researchers also observed an alarming increase in the targeting of the education sector. According to it, Transparent Tribe has been targeting India’s prestigious educational institutions such as the Indian Institutes of Technology (IITs), National Institutes of Technology (NITs), and business schools since May 2022. These attacks intensified in the first quarter of 2023, reaching their peak in February, the team notes.

"The subdivision of the Transparent Tribe, known as SideCopy, has also been identified targeting an Indian defence Organisation. Their modus operandi involves testing a domain hosting malicious file, potentially to serve as a phishing page," said the researchers.

The security team notes that the group dubbed as APT36 has cleverly utilised malicious PPAM files masquerading as "Officers posting policy revised final". For those unaware, a PPAM file is an add-in file used by Microsoft PowerPoint. "These files exploit macro-enabled PowerPoint add-ons (PPAM) to conceal archive files as OLE objects, effectively camouflaging the presence of malware," said the report.

In its report, Seqrite is recommending some preventive measures such as exercising caution while downloading files and opening email attachments from unsolicited or untrusted sources.

"Regularly update security software, operating systems, and applications to protect against known vulnerabilities. It is also important to implement robust email filtering and web security solutions to detect and block malicious content," the team advised.

Milestone Alert!
Livemint tops charts as the fastest growing news website in the world 🌏 Click here to know more.

Catch all the Elections News, Technology News and Updates on Live Mint. Download The Mint News App to get Daily Market Updates & Live Business News.
More Less
Updated: 26 Jun 2023, 11:46 AM IST
Next Story footLogo
Recommended For You
Switch to the Mint app for fast and personalized news - Get App