Skip to content

C0011 C0011

C0011 was a suspected cyber espionage campaign conducted by Transparent Tribe that targeted students at universities and colleges in India. Security researchers noted this campaign against students was a significant shift from Transparent Tribe‘s historic targeting Indian government, military, and think tank personnel, and assessed it was still ongoing as of July 2022.1

Item Value
ID C0011
Associated Names
First Seen December 2021
Last Seen July 2022
Version 1.0
Created 22 September 2022
Last Modified 22 September 2022
Navigation Layer View In ATT&CK® Navigator

Groups

ID Name References
G0134 Transparent Tribe 1

Techniques Used

Domain ID Name Use
enterprise T1583 Acquire Infrastructure -
enterprise T1583.001 Domains For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India.1
enterprise T1059 Command and Scripting Interpreter -
enterprise T1059.005 Visual Basic For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host.1
enterprise T1587 Develop Capabilities -
enterprise T1587.003 Digital Certificates For C0011, Transparent Tribe established SSL certificates on the typo-squatted domains the group registered.1
enterprise T1566 Phishing -
enterprise T1566.001 Spearphishing Attachment During C0011, Transparent Tribe sent malicious attachments via email to student targets in India.1
enterprise T1566.002 Spearphishing Link During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India.1
enterprise T1608 Stage Capabilities -
enterprise T1608.001 Upload Malware For C0011, Transparent Tribe hosted malicious documents on domains registered by the group.1
enterprise T1204 User Execution -
enterprise T1204.001 Malicious Link During C0011, Transparent Tribe relied on student targets to click on a malicious link sent via email.1
enterprise T1204.002 Malicious File During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email.1

Software

ID Name Description
S0115 Crimson For C0011, Transparent Tribe used an updated version of Crimson.1

References