NEW: Group Profiler — instant APT intel lookup. Try it →

Transparent Tribe

G0134 Pakistan MITRE ATT&CK →

Also known as: COPPER FIELDSTONE · APT36 · Mythic Leopard · ProjectM

Overview

Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.

Naming & attribution

Transparent Tribe is tracked under 5 names across the industry. It uses 14 documented ATT&CK techniques — more than 40% of the 174 groups tracked here. Activity attributed since at least 2013.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
COPPER FIELDSTONESecureworks
APT36Malhotra, A. et al
Mythic LeopardCrowdstrike
ProjectMFalcone, R. and Conant S

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Elderwood China — 7 shared techniques (44% overlap)
  • Machete — 7 shared techniques (39% overlap)
  • Mofang China — 5 shared techniques (33% overlap)
  • Mustard Tempest — 6 shared techniques (30% overlap)
  • TA2541 — 9 shared techniques (27% overlap)
  • TA459 China — 4 shared techniques (27% overlap)

Malware families with current indicators

2 families attributed to Transparent Tribe, carrying 317 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • DarkComet 303 indicators
  • ObliqueRAT 14 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Activists · Civil society · Government · Military

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203
  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 14 techniques across 5 tactics

Resource Development

Initial Access

Execution

Command and Control

Tools & malware (5)

DarkComet · ObliqueRAT · njRAT · Crimson · Peppy

Reporting (3)