By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT
Tech News

Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT

By Viral Trending Content 4 Min Read
Share
SHARE

Apr 14, 2025Ravie LakshmananCyber Attack / Malware

Pakistan-Linked Hackers

A threat actor with ties to Pakistan has been observed targeting various sectors in India with various remote access trojans like Xeno RAT, Spark RAT, and a previously undocumented malware family called CurlBack RAT.

The activity, detected by SEQRITE in December 2024, targeted Indian entities under railway, oil and gas, and external affairs ministries, marking an expansion of the hacking crew’s targeting footprint beyond government, defence, maritime sectors, and universities.

“One notable shift in recent campaigns is the transition from using HTML Application (HTA) files to adopting Microsoft Installer (MSI) packages as a primary staging mechanism,” security researcher Sathwik Ram Prakki said.

SideCopy is suspected to be a sub-cluster within Transparent Tribe (aka APT36) that’s active since at least 2019. It’s so named for mimicking the attack chains associated with another threat actor called SideWinder to deliver its own payloads.

Cybersecurity

In June 2024, SEQRITE highlighted SideCopy’s use of obfuscated HTA files, leveraging techniques previously observed in SideWinder attacks. The files were also found to contain references to URLs that hosted RTF files identified as used by SideWinder.

The attacks culminated in the deployment of Action RAT and ReverseRAT, two known malware families attributed to SideCopy, and several other payloads, including Cheex to steal documents and images, a USB copier to siphon data from attached drives, and a .NET-based Geta RAT that’s capable of executing 30 commands sent from a remote server.

The RAT is equipped to steal both Firefox and Chromium-based browser data of all accounts, profiles, and cookies, a feature borrowed from AsyncRAT.

“APT36 focus is majorly Linux systems whereas SideCopy targets Windows systems adding new payloads to its arsenal,” SEQRITE noted at the time.

CurlBack RAT and Spark RAT

The latest findings demonstrate a continued maturation of the hacking group, coming into its own, while leveraging email-based phishing as a distribution vector for malware. These email messages contain various kinds of lure documents, ranging from holiday lists for railway staff to cybersecurity guidelines issued by a public sector undertaking called the Hindustan Petroleum Corporation Limited (HPCL).

One cluster of activity is particularly noteworthy given its ability to target both Windows and Linux systems, ultimately leading to the deployment of a cross-platform remote access trojan known as Spark RAT and a new Windows-based malware codenamed CurlBack RAT that can gather system information, download files from the host, execute arbitrary commands, elevate privileges, and list user accounts.

Cybersecurity

A second cluster has been observed using the decoy files as a way to initiate a multi-step infection process that drops a custom version of Xeno RAT, which incorporates basic string manipulation methods.

“The group has shifted from using HTA files to MSI packages as a primary staging mechanism and continues to employ advanced techniques like DLL side-loading, reflective loading, and AES decryption via PowerShell,” the company said.

“Additionally, they are leveraging customized open-source tools like Xeno RAT and Spark RAT, along with deploying the newly identified CurlBack RAT. Compromised domains and fake sites are being utilized for credential phishing and payload hosting, highlighting the group’s ongoing efforts to enhance persistence and evade detection.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation

Klearcom announced as 2025 Technology Fast 50 company

Inside the Messy, Accidental Kryptos Reveal

€1.5m all-island project aims to restore oyster reefs to protect Irish coasts

Levoit Aero Cordless Vacuum Review: Self-Emptying Base

TAGGED: APT36, cyber espionage, Cyber Security, Cybersecurity, Indian Government, Internet, Malware, phishing, Remote Access Trojan, SEQRITE, SideCopy, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article 'Death is everywhere': Sudan camp residents shelter from attacks
Next Article Today in History: April 14, Abraham Lincoln fatally shot at Ford’s Theatre
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

How Ripple Is Taking Over The Asian Payments Market Using The XRP Ledger
Crypto
Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation
Tech News
Klearcom announced as 2025 Technology Fast 50 company
Tech News
Woman gets rare whole-life sentence for murder of French schoolgirl
World News
Government shutdown continues to add to stress on air traffic controllers and disrupt flights
Business
ApeCoin price forecast: weak bullish momentum signals risk ahead
Crypto
Isabelle Tate’s Cause of Death: What Happened to the ‘9-1-1: Nashville’ Actress?
Celebrity

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

How Ripple Is Taking Over The Asian Payments Market Using The XRP Ledger

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
How Ripple Is Taking Over The Asian Payments Market Using The XRP Ledger
October 24, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?