Colombo deplores war deaths, campaign attributed to the Pakistan-linked threat group APT36 also known as Transparent Tribe is raising concerns among cybersecurity researchers due to its unusual use of AI-generated malware code, sometimes referred to as “vibeware.” The campaign primarily targets Indian government networks and appears designed to quietly infiltrate systems while avoiding detection by traditional security tools.
Security analysts report that the attackers relied on sloppy or partially functional AI-generated code, a phenomenon increasingly observed in cybercrime where automated tools or AI assistants produce malware quickly but imperfectly. Despite these flaws, some components of the operation still managed to bypass security protections and harvest sensitive data.
How the Attack Campaign Works
The operation begins with social engineering tactics intended to trick victims into opening malicious files. Attackers distribute fraudulent résumé PDFs and weaponized Google Sheets documents, which serve as the initial entry point into targeted systems. These files appear harmless at first glance, making them more likely to bypass initial scrutiny.
Once the victim interacts with the document, the attackers deploy a surveillance utility called BackupSpy, which scans the infected machine’s local drives and connected USB devices. This reconnaissance stage allows the attackers to locate valuable files and determine where additional malware should be deployed.
From there, the attackers attempt to push additional payloads containing the so-called vibeware, which includes code fragments believed to be generated or heavily assisted by AI tools. These scripts are often poorly structured or incomplete—one variant reportedly lacked a destination server for sending stolen data—but they still demonstrate how attackers are experimenting with AI-assisted development.
Credential Theft Using LuminousCookie
Among the tools discovered in the campaign was a credential-stealing component known as LuminousCookie. Unlike some of the faulty malware samples, this tool proved effective at bypassing App-Bound Encryption, a security mechanism designed to protect browser-stored credentials.
By circumventing that protection, LuminousCookie can extract saved usernames, passwords, and session tokens from web browsers. This data could potentially give attackers access to government portals, internal communication systems, or other sensitive services.
Obfuscation and False Flags
Researchers also noted attempts to obscure the true origin of the attack. The malware code reportedly includes the common Hindu surname “Kumar,” likely inserted to create a misleading attribution trail that could suggest the campaign originated in India rather than elsewhere.
Additionally, command-and-control infrastructure used by the attackers included a Discord server referencing a character from the popular anime Sung Jin-Woo from the series Solo Leveling. Using pop-culture references and legitimate communication platforms is a common tactic to blend malicious traffic with normal internet activity.
Why AI-Generated Malware Is Concerning
While the vibeware used in this campaign contained obvious mistakes, cybersecurity experts warn that AI-assisted malware development is evolving rapidly. Attackers can now:
- Generate malware prototypes faster than ever
- Experiment with multiple variants simultaneously
- Automate phishing and code obfuscation techniques
- Lower the technical barrier for new cybercriminals
Even poorly written code can be dangerous if just one component works effectively, as demonstrated by the successful credential-stealing capability observed in this campaign.
Read More: Israel pounds Beirut in expansion of war; Trump demands say over new Iranian leader
FAQs
What is APT36?
APT36 is a cyber-espionage group believed to operate in alignment with Pakistani strategic interests. Also known as Transparent Tribe, it has historically targeted Indian government, defense, and diplomatic organizations.
What does “vibeware” mean in cybersecurity?
“Vibeware” is an informal term used by researchers to describe AI-generated or poorly structured malware code that appears to be produced quickly using automated tools rather than carefully engineered by human developers.
How did the attackers initially infect victims?
The campaign used phishing tactics, distributing fake résumé PDFs and malicious Google Sheets documents that trick victims into executing hidden payloads.
What is the BackupSpy tool used for?
BackupSpy acts as a watcher utility that scans an infected system’s drives and USB devices. It helps attackers locate sensitive files and decide where to deploy additional malware components.
Why include names like “Kumar” in the malware code?
Attackers sometimes insert false clues or “false flags” into code to mislead investigators and shift blame toward another country or group.
Conclusion
The latest campaign linked to APT36 highlights a growing trend in cybercrime: the experimental use of AI-generated malware. Even though much of the vibeware in this operation was poorly written or incomplete, certain tools such as the credential-stealing LuminousCookie module proved capable of bypassing security protections and stealing sensitive data.As AI tools become more accessible, cybersecurity experts expect more frequent and more sophisticated AI-assisted attacks. Organizations, especially government and defense sectors, must strengthen email security, implement stricter document-handling policies.
