THREATOPS Actor Dossier
LIVE ← Dashboard

Transparent Tribe

G01343 reports
aliases · Transparent Tribe · COPPER FIELDSTONE · APT36 · Mythic Leopard · ProjectM
Export dossier:
3
Reports
6
Techniques
6
Tactics
2
Countries
100%
Hunt coverage
5
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1213.002 (Sharepoint), T1588.006 (Vulnerabilities), T1053.005 (Scheduled Task).
  • Primary targeting: IN, US.
  • Resurgent after a quiet period: 2 report(s) in last 30d vs 0 prior (+100%).
  • Recent movement: 4 new technique(s), 7 new infrastructure indicator(s) in the last 30 days.
  • Hunt coverage 100% of 6 observed techniques (0 gap(s)).
  • Assessment confidence: medium (60).

Activity & trend

ResurgentLast 30d: 2 vs 0 prior (+100%)· first reported 2026-07-10 · last 2026-09-18
2
7d
2
30d
3
90d
3
All
0.2
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

New techniques
T1053.005T1027.009T1059.001T1589.001
Targeting gained
INUS
New infrastructure
https://f005.backblazeb2.com/file/Clienthttps://clients-easy.s3.us-east-005.backhttp://ip-api.com/jsonhttps://ipinfo.io/jsoncurlhttps://ipapi.co/jsonRetrieveindiatodays.orgurltheprints.org

Vulnerabilities in this actor's reporting · 57

Overview

Analyst triage
Intelligence summary

Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.(Citation: Proofpoint Operation Transparent Tribe March 2016)(Citation: Kaspersky Transparent Tribe August 2020)(Citation: Talos Transparent Tribe May 2021)

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected