Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Transparent Tribe

🇵🇰Transparent Tribe

🇵🇰 Transparent Tribe is a tracked threat actor in the Clankerusecase corpus. Attributed to PK. Primary motivation: State. We map 24 detection use cases to this actor across 29 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-08-13 to 2026-08-13.

crit 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0134) ↗
24Use cases
1Articles
29Techniques
3IOCs

Known aliases

Transparent TribeAPT36Mythic LeopardOperation C-MajorCOPPER FIELDSTONEProjectM

Top techniques

All other tracked techniques

Detection use cases (24)

PATCHCORD 'BeaconBrowserHijack' Run-key persistence (APT36) Bespoke PATCHCORD/SHEETCORD browser shortcut (.lnk) hijack write Bespoke PATCHCORD C2 beacon to appstoore.solutions / 46.30.188.13:8080 Bespoke PATCHCORD delivery via TMS_AfghanTelecom.exe Inno Setup installer / known hashes Bespoke SHEETCORD VBS Startup-folder persistence drop Bespoke Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Asset exposure — vulnerability matches article CVE(s) Internal Phishing-link click correlated to endpoint execution Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal PowerShell encoded / obfuscated command Internal AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process MITRE match AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay MITRE match Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access MITRE match Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes MITRE match Package manager lifecycle hook spawns network-fetching shell or runtime MITRE match Service-process parent spawns subprocess containing CLI-argument-injection tokens MITRE match Abnormal Security: malicious email opened MITRE match Click on URL whose host doesn't match the sender domain MITRE match Email attachment opened from external sender MITRE match

Threat-intel articles (1)

Tracked indicators

Domains (2)

appstoore.solutions nic-support.site

IP addresses (1)

46.30.188.13

CVEs (1)

CVE-2024-6387