Threat Actor Profile

Mythic Leopard

Mythic Leopard, also known as Transparent Tribe or APT36, is a Pakistan-linked advanced persistent threat (APT) group active since at least 2013. This state-sponsored actor primarily targets Indian government, military, and defense sectors, employing spear-phishing, malware, and deceptive infrastructure to conduct cyber-espionage operations.

Threat Actor Profile

Mythic Leopard

Fancy Bear TTPs

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Country of Origin

Mythic Leopard is widely attributed to Pakistan, with evidence such as time zone settings and network providers linking their operations to the region.

Members

The exact size and composition of the group are unclear. They operate under aliases such as Transparent Tribe, Earth Karkaddan, and ProjectM, indicating a coordinated and state-aligned structure.

Leadership

The leadership of Mythic Leopard remains unknown. However, their activities suggest alignment with Pakistan's military or intelligence services.

Tactics

The group focuses on cyber-espionage, targeting Indian defense, government, and critical infrastructure sectors to gather intelligence.

Techniques

  • Spear-phishing emails with malicious attachments.

  • Use of fake government portals and malvertising campaigns.

  • Deployment of malware such as Crimson RAT, ObliqueRAT, and CapraRAT.

Procedures

  • Leveraging cross-platform programming languages like Python and Golang.

  • Utilizing cloud services like Telegram, Slack, and Google Drive for command-and-control (C2) operations.

Employing USB-based malware for air-gapped systems.

Want to shut down threats before they start?

Indicators of Compromise (IOCs)

Organizations should monitor for:

  • Known Fancy Bear malware signatures (e.g., XAgent, ADVSTORESHELL).
  • Suspicious domains mimicking government or defense entities.
  • Zero-day exploits in applications like Microsoft Windows and Adobe Flash.
  • Abnormal network traffic patterns indicating command-and-control communications.

Key Victims

Fancy Bear targets include:

  • Governments (United States, Germany, France, Ukraine, and others).
  • Military Organizations (focus on NATO-aligned entities).
  • Media Outlets and Journalists (especially those covering Kremlin-related topics).
  • Critical Infrastructure (energy, aerospace, and defense).
  • International Sporting Organizations (e.g., WADA).
  • Political Groups (e.g., the Democratic National Committee).

Notable Cyber Attacks

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Notable Cyberattacks

  • Spear-phishing campaigns targeting the Indian Department of Defense Production (DDP) and aerospace sector.

  • Distribution of malicious ISO images targeting the Indian Air Force.

Glitch effectGlitch effect

How to Defend Against Mythic Leopard

1

Implement email filtering and block macro-enabled Office files.

2

Monitor DNS queries for typosquatted domains.

4

Enforce phishing-resistant multi-factor authentication (MFA).

5

Harden cloud services and educate employees on phishing tactics.

Huntress solutions help protect organizations by monitoring endpoints, detecting intrusions, and mitigating Fancy Bear threats withenterprise-grade technology.

Law Enforcement & Arrests

No arrests have been reported. However, the group's activities are closely monitored by cybersecurity organizations and law enforcement agencies.

References

Related Threat Actor Profiles

Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.

Detect, Respond, Protect

See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.

Try Huntress for Free