← Back to Pulse Feed
PULSE DETAIL
APT36 has been observed utilizing two distinct methods to execute malware on Linux and Windows platforms, focusing on the distribution of malicious files disguised as legitimate documents.
On Linux, the attack begins with the creation of a `.local` directory with specific permissions (0755), followed by downloading three files from a target URL: `gkt3.1`, `http://gkt3.sh`, and `APPL FOR UPDATION.pdf`. The `http://gkt3.sh` script is executed after this download, which subsequently utilizes the `xdg-open` command to open the PDF file, potentially leading to further exploitation or malware execution.
Conversely, on Windows platforms, APT36 employs a malicious shortcut (LNK file) named `APPL FOR UPDATION OF NAME BASED & OFFICIAL NIC E-MAIL ID.pdf.LNK`. This file initiates the execution of embedded code through the use of the `mshta.exe` tool, a legitimate Windows system application.
Indicators of Compromise (17 / 50 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 1426bdff1ef4466c37631a51c2ba6e48 | — | 2025-12-21 | |
| FileHash-MD5 | 180c88e45db8a2bcc095f32ca71ab8f6 | — | 2025-12-21 | |
| FileHash-MD5 | 24e010830cbb42384bf609f8acf91c46 | — | 2025-12-21 | |
| FileHash-MD5 | 30fda797535a0f367ea2809426760020 | — | 2025-12-21 | |
| FileHash-MD5 | 403ea69b8b75e16a644d12053eb2659a | — | 2025-12-21 | |
| FileHash-MD5 | 40ef50cc91a890ecb7726a72fe130424 | — | 2025-12-21 | |
| FileHash-MD5 | 57ba3d1bfc8724668c52b98908bf159a | — | 2025-12-21 | |
| FileHash-MD5 | 5a9552f5d8bb031358cbacf827624186 | — | 2025-12-21 | |
| FileHash-MD5 | 689af44a940f293ea659603aee2323b3 | — | 2025-12-21 | |
| FileHash-MD5 | 75245a9be77dc6014e079cf249a98ab3 | — | 2025-12-21 | |
| FileHash-MD5 | 813b69e1ffeb70cdd5a63a8103a896d3 | MD5 of 6cadcdb2c2cd1425a44fe08e00c4cfcff9498ee0 | 2025-12-21 | |
| FileHash-MD5 | 90796ed66e7f5f36b6317e6bdf9718ce | — | 2025-12-21 | |
| FileHash-MD5 | a4f1cc3537eb8dd669c3cc16cdf7b798 | — | 2025-12-21 | |
| FileHash-MD5 | a53b1134f5bad31b407f5f597fd1cfa3 | — | 2025-12-21 | |
| FileHash-MD5 | c345c4a04df2d324f594e2ae9040daf8 | — | 2025-12-21 | |
| FileHash-MD5 | ceb715db684199958aa5e6c05dc5c7f0 | — | 2025-12-21 | |
| FileHash-MD5 | de035f212161f33accc610793fdcaa67 | MD5 of e0e89ee546fe04498aee0e1deb33e0b47ba8708a | 2025-12-21 |
References (1)