🇵🇰Transparent Tribe
🇵🇰 Transparent Tribe is a tracked threat actor in the Clankerusecase corpus. Attributed to PK. Primary motivation: State. We map 24 detection use cases to this actor across 29 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-08-13 to 2026-08-13.
crit 1
24Use cases
1Articles
29Techniques
3IOCs
Known aliases
Transparent TribeAPT36Mythic LeopardOperation C-MajorCOPPER FIELDSTONEProjectM
Top techniques
All other tracked techniques
T1027 · Obfuscated Files or InformationT1027.002 · Software PackingT1027.013 · Encrypted/Encoded FileT1036.005 · Match Legitimate Resource Name or LocationT1059.005 · Visual BasicT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1539 · Steal Web Session CookieT1547.001 · Registry Run Keys / Startup FolderT1547.009 · Shortcut ModificationT1555.003 · Credentials from Web BrowsersT1564.001 · Hidden Files and DirectoriesT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1568 · Dynamic ResolutionT1571 · Non-Standard PortT1583.001 · DomainsT1584.001 · DomainsT1608.004 · Drive-by Target
Detection use cases (24)
PATCHCORD 'BeaconBrowserHijack' Run-key persistence (APT36) PATCHCORD/SHEETCORD browser shortcut (.lnk) hijack write PATCHCORD C2 beacon to appstoore.solutions / 46.30.188.13:8080 PATCHCORD delivery via TMS_AfghanTelecom.exe Inno Setup installer / known hashes SHEETCORD VBS Startup-folder persistence drop Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Infostealer — non-browser process accessing browser cookie/login DBs Asset exposure — vulnerability matches article CVE(s) Phishing-link click correlated to endpoint execution Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) PowerShell encoded / obfuscated command AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Developer package install spawning script-host with non-registry C2 within 5 minutes OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Package manager lifecycle hook spawns network-fetching shell or runtime Service-process parent spawns subprocess containing CLI-argument-injection tokens Abnormal Security: malicious email opened Click on URL whose host doesn't match the sender domain Email attachment opened from external senderThreat-intel articles (1)
Tracked indicators
Domains (2)
appstoore.solutions nic-support.siteIP addresses (1)
46.30.188.13CVEs (1)
CVE-2024-6387