Researchers from Bitdefender have revealed that the Pakistan-aligned threat actor Transparent Tribe (also known as APT36) has begun using AI-powered coding tools to mass-produce a high volume of malware implants targeting Indian entities.
Key Aspects of the AI-Driven Campaign
The shift marks a transition from bespoke, hand-crafted malware to an “industrialized” approach designed to overwhelm traditional defenses.
- Vibeware Development: The group is using “vibe-coding”—a practice where natural language prompts are used with AI tools to generate functional code.
- Polyglot Binaries: By leveraging AI, the actors can quickly produce implants in lesser-known programming languages such as Nim, Zig, and Crystal. This diversity makes it difficult for signature-based security tools to keep up with the constant stream of new, unique samples.
- Distributed Denial of Detection (DDoD): Researchers characterize this strategy as a “DDoD” attack against security telemetry, where the goal is to flood target environments with a “mediocre mass” of disposable binaries that are hard to track individually.
New Malware Implants
The campaign features several AI-assisted tools that abuse trusted cloud services for command-and-control (C2) to blend in with legitimate traffic:
- Warcode & CrystalShell (Crystal): Shellcode loaders and backdoors (targeting Windows, Linux, macOS) utilizing Discord for C2.
- ZigShell (Zig): Backdoor leveraging Slack for C2 infrastructure.
- SupaServ & LuminousStealer (Rust): Backdoors using Supabase/Firebase and infostealers using Google Drive/Firebase.