A new cyber-espionage campaign attributed to the Pakistan-linked threat group APT36, also widely known as Transparent Tribe, has drawn attention from cybersecurity researchers due to its unusual reliance on AI-generated malware code, sometimes referred to as “vibeware.”
According to security analysts, the campaign appears to target Indian government networks and attempts to quietly infiltrate systems while avoiding triggering conventional security defenses. Reports indicate that the attackers experimented with loosely structured or partially functional code likely generated with AI assistance, signaling a growing trend in which threat actors leverage automated tools to rapidly produce malware.
Social Engineering as the Entry Point
The attack begins with carefully crafted phishing and social engineering tactics designed to deceive victims. Researchers observed that the attackers distributed fraudulent résumé PDF files and weaponized Google Sheets documents to trick recipients into opening malicious attachments.
Once opened, these documents trigger hidden payloads that establish an initial foothold inside the victim’s system. This method allows attackers to bypass basic security filters because the files appear legitimate and are often disguised as job applications or professional documents.
BackupSpy Used for System Surveillance
After gaining access, the attackers deploy a monitoring utility known as BackupSpy. This tool functions as a watcher program, continuously scanning the compromised system for useful information.
BackupSpy analyzes local drives, external storage, and connected USB devices, helping attackers identify files, credentials, and sensitive data worth targeting. Once valuable resources are detected, the attackers attempt to deploy additional malware components—the so-called vibeware.
However, analysts from the cybersecurity company Bitdefender noted that several of these AI-generated tools were poorly implemented or incomplete, suggesting automated generation rather than careful human coding. In one case, a malware component lacked a proper server address for transmitting stolen data, rendering it ineffective.
LuminousCookie Successfully Steals Credentials
Despite the flaws in some tools, one component proved significantly more capable. The credential-stealing malware LuminousCookie successfully bypassed App-Bound Encryption, a security feature designed to protect browser-stored credentials.
By circumventing this protection mechanism, LuminousCookie can extract saved usernames, passwords, and authentication tokens from popular web browsers. Such information could allow attackers to access email accounts, internal government portals, or other restricted systems.
False Flags and Obfuscation Tactics
Researchers also discovered signs of intentional misdirection within the malware’s code. One notable example is the inclusion of the common Hindu surname “Kumar,” likely inserted to create a false attribution trail suggesting that the attack originated in India rather than elsewhere.
To further obscure their activity, the attackers used a Discord server as part of their command-and-control infrastructure. The server reportedly referenced the protagonist Sung Jin‑Woo from the popular anime series Solo Leveling. Using pop-culture references and mainstream platforms like Discord allows attackers to blend malicious traffic with normal online communication, making detection more difficult.
The Growing Role of AI in Malware Development
The emergence of vibeware highlights a broader trend in cybersecurity: attackers experimenting with AI-assisted code generation. While the malware in this campaign contained several errors, the approach offers threat actors advantages such as:
- Rapid generation of malware variants
- Reduced development time for cyber tools
- Lower technical barriers for less experienced attackers
- Ability to quickly test and modify attack methods
Even imperfect code can pose a serious risk if one functional component, like a credential stealersuccessfully operates within a compromised system.
Read More: Apple M5 Max Beats Desktop M3 Ultra in Benchmarks
FAQs
What is APT36?
APT36, also known as Transparent Tribe, is a cyber-espionage group known for targeting government, defense, and diplomatic organizations, particularly in South Asia.
What does “vibeware” mean?
Vibeware refers to AI-generated or poorly structured malware code that appears to have been produced rapidly using automated tools rather than carefully developed by human programmers.
How did the attackers initially infect victims?
The attackers used phishing emails containing fake résumé PDFs and malicious Google Sheets documents that trick victims into opening infected files.
What role does BackupSpy play in the attack?
BackupSpy acts as a monitoring and reconnaissance tool, scanning system drives and connected USB devices to identify valuable data and determine where additional malware should be deployed.
Why did the attackers reference “Kumar” and an anime character?
These elements likely serve as obfuscation and misdirection tactics. The name “Kumar” may be intended to shift blame toward India, while anime references help disguise malicious infrastructure within seemingly harmless online communities.
Conclusion
The latest campaign linked to APT36 illustrates how cyber threat actors are increasingly experimenting with AI-assisted malware development. Although much of the vibeware deployed in this operation was flawed or incomplete, the successful use of tools like LuminousCookie demonstrates that even imperfect AI-generated code can still cause significant damage. As AI technology becomes more accessible, cybersecurity experts expect a rise in rapidly generated malware variants and automated cyber-espionage campaigns. Organizations, especially those in government and critical sectors, must strengthen phishing defenses, monitor credential access patterns, and implement robust endpoint security to mitigate the risks posed by this evolving threat landscape.
