ESET reported that Transparent Tribe (also tracked as APT36) ran an Android espionage campaign that used trojanized messaging apps, MeetsApp and MeetUp, to infect people in India and Pakistan who likely had military or political relevance. The operation appears to have relied on honey-trap romance lures, directing targets to fake download sites instead of Google Play, while the apps retained normal chat features to avoid suspicion and covertly installed the CapraRAT backdoor.
Once installed, the malware enabled broad surveillance, including screenshots, photo capture, audio and call recording, SMS access, contact theft, file exfiltration, and location tracking. ESET linked the activity to Transparent Tribe through reused CapraRAT code, shared command-and-control infrastructure, the same signing certificate, and overlap with domains previously tied to the group; researchers also said poor operator security exposed victim data, allowing them to identify more than 150 victims across India, Pakistan, Russia, Oman, and Egypt.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On March 7, 2023, ESET published findings on an active Transparent Tribe espionage campaign involving trojanized Android messaging apps that retained chat features while adding spyware capabilities such as screenshot capture, audio recording, SMS access, contact theft, file exfiltration, and location tracking. ESET linked the activity to Transparent Tribe through shared infrastructure, reused CapraRAT code, the same C2 server and signing certificate, and said poor operator security exposed victim PII from more than 150 victims across several countries.
ESET reported that a Transparent Tribe (APT36) campaign using trojanized Android apps named MeetsApp and MeetUp to deliver the CapraRAT backdoor appears to have been active since at least July 2022. The operation likely used romance-scam-style lures and fake distribution websites to target people in India and Pakistan with likely military or political relevance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.