Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
New Case Study: Credit Union Boosts Threat Prevention & Detection with Cymulate
Learn More
New Research: Cymulate Research Labs Discovers Token Validation Flaw
Learn More
An Inside Look at the Technology Behind Cymulate
Learn More

APT36 Targets Indian Defense Research And Development Organization (DRDO)

March 29, 2023

A recent APT36 campaign began with spam email which contained a link to a malicious file hosted on a compromised website. Mshta.exe was then used to connect to a specific URL and execute a Microsoft HTML Application file which decoded and decompressed a PowerPoint file within a temporary folder. The PPT file then loaded a DLL file into memory which was triggered using the DynamicInvoke method. The final payload was remote access trojans used to exfiltrate sensitive information including clipboard data screenshots keystrokes and a list of files and folders.