Threat group.View on attack.mitre.org
Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
Transparent Tribe has dropped encoded executables on compromised hosts. |
| T1036.005 Match Legitimate Resource Name or Location |
Transparent Tribe can mimic legitimate Windows directories by using the same icons and names. |
| T1059.005 Visual Basic |
Transparent Tribe has crafted VBS-based malicious documents. |
| T1189 Drive-by Compromise |
Transparent Tribe has used websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
| T1203 Exploitation for Client Execution |
Transparent Tribe has crafted malicious files to exploit CVE-2012-0158 and CVE-2010-3333 for execution. |
| T1204.001 Malicious Link |
Transparent Tribe has directed users to open URLs hosting malicious content. |
| T1204.002 Malicious File |
Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems. |
| T1564.001 Hidden Files and Directories |
Transparent Tribe can hide legitimate directories and replace them with malicious copies of the same name. |
| T1566.001 Spearphishing Attachment |
Transparent Tribe has sent spearphishing e-mails with attachments to deliver malicious payloads. |
| T1566.002 Spearphishing Link |
Transparent Tribe has embedded links to malicious downloads in e-mails. |
| T1568 Dynamic Resolution |
Transparent Tribe has used dynamic DNS services to set up C2. |
| T1583.001 Domains |
Transparent Tribe has registered domains to mimic file sharing, government, defense, and research websites for use in targeted campaigns. |
| T1584.001 Domains |
Transparent Tribe has compromised domains for use in targeted malicious campaigns. |
| T1608.004 Drive-by Target |
Transparent Tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.