The Containment Era is here. →Explore

Executive Summary

In August and September 2025, the state-sponsored hacking group APT36 (also known as Transparent Tribe) launched a spear-phishing campaign targeting Indian government entities. The campaign delivered a new variant of a Golang-based remote access trojan, DeskRAT, which allowed attackers to gain persistent access, conduct reconnaissance, and exfiltrate sensitive information. The phishing emails, likely crafted to impersonate trusted sources, succeeded in infecting victim networks, enabling APT36 to conduct espionage activities against high-profile targets, further compromising Indian national security interests.

This incident underscores the persistent risk posed by well-resourced, nation-state threat actors using continuously evolving malware families and novel programming languages like Golang. The rise of such campaigns highlights an urgent need for improved east-west traffic monitoring, zero trust network segmentation, and advanced user awareness against targeted phishing techniques.

Why This Matters Now

Nation-state campaigns like APT36’s DeskRAT operation demonstrate the rapid evolution of attacker tools and techniques, including the adoption of Golang for malware development and multi-stage spear-phishing. Organizations, especially in the public sector, must urgently reassess and strengthen their segmentation, threat detection, and email security posture to defend against modern espionage threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The campaign highlighted insufficient east-west traffic security, inadequate phishing detection, and a lack of zero trust segmentation, increasing the risk of lateral movement and data exfiltration.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust Segmentation, granular east-west traffic controls, egress filtering, and real-time threat detection aligned to CNSF principles would have restricted attacker movement, identified anomalous activity, and blocked data exfiltration throughout the DeskRAT campaign. Segmented network boundaries and explicit policy enforcement could sharply constrain lateral movement and limit the blast radius from any initial compromise.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Early detection of phishing payloads or anomalous access on ingress.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-based policy prevents unauthorized privilege escalation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement attempts blocked or detected between workloads.

Command & Control

Control: Cloud Firewall (ACF)

Mitigation: Suspicious outbound C2 traffic is blocked and alerted.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Exfiltration attempts via unapproved egress channels are stopped.

Impact (Mitigations)

Rapid response and containment of affected segments.

Impact at a Glance

Affected Business Functions

  • Government Operations
  • Defense Communications
  • Administrative Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive government documents, defense strategies, and personal information of government employees.

Recommended Actions

  • Enforce zero trust segmentation and east-west policy within cloud and hybrid environments to reduce attacker lateral movement.
  • Deploy continuous anomaly-based detection and automated threat response to rapidly identify suspicious behaviors like DeskRAT C2 activity.
  • Implement strict egress filtering and FQDN-based policies to prevent unauthorized data exfiltration or shadow communication.
  • Centralize visibility and control to enable swift containment and isolation of compromised segments.
  • Regularly audit privileges and segmentation policies to ensure least privilege and compliance alignment across cloud workloads.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image