Listen to this Post
A New Wave of Phishing Threatens India’s National Security Infrastructure
In an alarming escalation of cyber warfare in South Asia, Pakistani state-sponsored hackers known as APT36 (Transparent Tribe) have launched a sophisticated phishing campaign against Indian government institutions. By impersonating India’s National Informatics Centre (NIC), the attackers are attempting to steal sensitive credentials and classified information through a forged domain that looks deceptively authentic.
The malicious campaign revolves around the domain “accounts.mgovcloud[.]in.departmentofdefence[.]live”, designed to mimic NIC’s trusted eEmail services—a system heavily relied upon by Indian ministries and defense offices. The attackers’ strategy is simple yet deadly: they send fake login pages to government officials, tricking them into entering credentials that are then transmitted to APT36’s remote command servers.
The parent domain, “departmentofdefence[.]live,” cleverly invokes India’s Ministry of Defence, adding another layer of authenticity to the trap. This calculated psychological play aims to exploit the trust government officials place in familiar-looking domains, enabling the attackers to breach critical systems undetected.
A Multi-Layered Cyber Operation
Researchers uncovered a complex command-and-control (C2) infrastructure supporting the campaign. Two key IP addresses—81.180.93[.]5 and 45.141.59[.]168—serve as the backbone of the operation. The first hosts a Stealth Server C2 running on a non-standard port (8080), an intentional choice to blend malicious activity with legitimate web traffic and avoid detection.
This “stealth” configuration enables continuous remote access to compromised systems. Once an Indian government system is infiltrated, the attackers can execute commands, exfiltrate classified data, and deploy further malware payloads—all while maintaining communication through backup servers.
Such redundancy reflects the high sophistication and persistence of APT36. Even if one C2 node is discovered and blocked, another swiftly takes over. This resilience underscores the group’s growing operational maturity and long-term focus on intelligence collection from Indian defense and diplomatic assets.
APT36’s Long Game: A Persistent Threat
APT36 has been an active adversary against India for over a decade, repeatedly refining its techniques. Initially known for crude spear-phishing emails containing malicious documents, the group has now evolved to leverage domain spoofing, encrypted C2 channels, and social engineering to a degree previously unseen.
Its objectives align with Pakistan’s broader intelligence goals—surveillance, infiltration, and data theft from Indian government entities. Every successful breach potentially exposes strategic defense data, diplomatic communications, or infrastructure blueprints. In the modern hybrid warfare landscape, such information is as valuable as any military weapon.
Government and Organizational Response
Indian cybersecurity experts are urging immediate countermeasures. Recommended actions include:
Implementing strong email authentication (DMARC, SPF, and DKIM) to block spoofed messages.
Mandatory multi-factor authentication (MFA) across all government email platforms.
Monitoring outbound network traffic for unusual connections to the two identified IP addresses.
Conducting staff awareness training to help employees identify suspicious links and spoofed domains.
By combining these defensive layers, India can significantly reduce exposure to future phishing campaigns of this magnitude. Yet, experts caution that as APT36 continues to adapt, the threat landscape will remain volatile and unpredictable.
What Undercode Say:
APT36’s recent campaign represents a strategic evolution rather than a one-off attack. The use of NIC impersonation is particularly concerning, as it reflects an understanding of India’s internal communication ecosystem. Such insight implies prior reconnaissance or insider knowledge, which elevates the campaign beyond ordinary phishing.
From a geopolitical standpoint, this is cyber espionage operating under the veil of plausible deniability. Pakistan has long denied sponsoring hacking collectives like Transparent Tribe, but the consistency, targets, and technical infrastructure suggest state alignment. Each campaign is part of a larger intelligence mosaic—one where stolen credentials can later enable deeper network penetration or targeted sabotage.
The dual-IP and Stealth Server setup also indicates a shift toward cloud-resilient attack models. These are harder to track and neutralize, especially when attackers rotate IPs or host components in legitimate cloud services. Such techniques blur the line between malicious and benign traffic, challenging even advanced security monitoring systems.
Moreover, this operation demonstrates how psychological manipulation and technical expertise converge. By using familiar government-associated URLs, APT36 weaponizes trust. Their goal is not merely to breach systems but to do so quietly, methodically, and with minimal traces—hallmarks of modern espionage.
Indian authorities should interpret this as a wake-up call for cyber defense modernization. Beyond blocking domains, there’s a need to integrate behavioral analytics, threat intelligence sharing, and real-time anomaly detection across ministries. Traditional perimeter defenses are insufficient when adversaries exploit human trust rather than system vulnerabilities.
The broader implication is that state-sponsored cyber conflict in South Asia is entering a mature phase. Unlike earlier defacement or propaganda attacks, today’s operations are about strategic intelligence and stealth. The digital battlefield now mirrors geopolitical tensions, with hackers replacing spies and phishing links replacing diplomatic cables.
In essence, APT36’s move symbolizes an arms race in cyberspace—one where both nations continuously evolve their digital arsenals. As India strengthens its cyber posture, APT36 and similar actors will undoubtedly innovate new methods. Vigilance, rapid threat response, and continuous awareness are the only sustainable defenses.
🔍 Fact Checker Results
✅ APT36 (Transparent Tribe) is a verified Pakistani state-sponsored hacking group targeting India.
✅ The spoofed domain “departmentofdefence[.]live” and related IPs were identified by cybersecurity researchers.
✅ Indian agencies have issued advisories recommending email authentication and MFA as immediate countermeasures.
📊 Prediction
🧠 Expect more domain-spoofing campaigns in 2026, with APT36 likely to imitate additional Indian ministries.
⚙️ India will accelerate zero-trust architecture adoption across government networks to curb phishing-based breaches.
🌐 Regional cyber conflict will intensify, as both nations increasingly weaponize digital espionage as a tool of diplomacy.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




