September 8, 2026
- SideCopy / Transparent Tribe activity against Indian defence targets continues with the same LNK plus BAT/PowerShell tradecraft. Qihoo 360's Advanced Threat Research Institute published further CrimsonRAT samples and a separate Go-based RAT, with infrastructure reuse across both campaigns (360 ATRI report).
· Threat Activity
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
August 23, 2026
- Transparent Tribe has refreshed its toolset for operations against Afghan government targets, succeeding against less mature Taliban-run organisations while failing against better-defended Indian agencies (Dark Reading).
· Threat Activity
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick
July 2, 2026
- TransparentTribe (APT36) is weaponizing the 2026 Indian NEET exam-leak controversy as a lure, deploying the Go-based StealthServer backdoor (Windows counterpart of DeskRAT) with WebSocket C2. FalconFeeds.
· Threat Activity
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US
June 18, 2026
- SideCopy (APT36 / Transparent Tribe) continues its double-extension LNK → PowerShell → CrimsonRAT chain against Indian defense, swapping lures between fake PowerPoint briefings and Word "Minutes of Meeting" docs; staged components barely register at delivery. IOCs via Nextron (Nextron).
· Threat Activity & Ransomware
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel