Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Priyanka Chopra brings the colors of Sylvia Cherassi to Cannes Lions 2026

Aooo Talk Road to second album “Rooom”: Interview

Katei announces the latest information on Manon’s hiatus, warns against making assumptions

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » APT36 SPOOFS INDIA POST website infects Windows and Android users with malware
Celebrities

APT36 SPOOFS INDIA POST website infects Windows and Android users with malware

By March 27, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 27, 2025Ravi LakshmananMobile Security/Malware

India Post Website

The Advanced Persistent Threat (APT) group with ties to Pakistan is attributed to the creation of fake websites decorated in Indian public sector postal systems as part of a campaign designed to infect both domestic windows and Android users.

Cybersecurity company Cyfirma attributes the campaign to a threat actor called APT36, also known as the Transparent Tribe.

A fraudulent website that mimics an Indian post is named “Postindia”.[.]site. “Who lands on the site from Windows Systems will be asked to download the PDF document, but users accessing from Android devices will be provided with a malicious application package (“indiapost.apk”) file.

Cybersecurity

“When accessed from the desktop, the site provides malicious PDF files containing the ‘Clickfix’ tactic,” Cyfirma said. “This document tells the user to press Win + R, paste the provided PowerShell command into the Run dialog and run it – it could compromise the system.”

An analysis of EXIF ​​data associated with dropped PDFs shows that it was created on October 23, 2024 by an author named “PMYLS”. The domain impersonating India Post was registered on November 20th, 2024, about a month later.

India Post Website

The PowerShell code is designed to download the next stage payload from a remote server (“88.222.245[.]211”) It is currently inactive.

Meanwhile, when the same site accesses from an Android device, it will install mobile apps to encourage users to have a “better experience.” Once installed, this app requires extensive permissions to harvest and remove sensitive data, including contact lists, current locations, and files from external storage.

Cybersecurity

“Android apps change icons to mimic unsuspecting Google account icons to hide activity, making it difficult for users to find and uninstall apps when they want to delete them,” the company said. “This app also has the ability to force users to accept permissions if denied on the first instance.”

Malicious apps are designed to continue running in the background after the device is restarted, while explicitly looking for permission to ignore battery optimization.

“Clickfix is ​​increasingly being exploited by cybercriminals, fraudsters and APT groups, as reported by other researchers observing its use in the wild,” Cyfirma said. “This new tactic poses a serious threat because it can target both unsuspecting and tech-savvy users who may not be familiar with such methods.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe new report explains why CASB solutions can’t deal with Shadowers and how to fix it
Next Article Animoca Brands Sonyium By Sony Block Solutions Labs will partner with Moca Network’s ID layer and launch San Frantokyo’s animation initiative on Soneium

Related Posts

Priyanka Chopra brings the colors of Sylvia Cherassi to Cannes Lions 2026

June 25, 2026

Olivia Wilde customizes Saint Laurent at LA premiere of ‘The Invite’

June 25, 2026

Penelope Cruz wears Chanel on ice at Los Angeles premiere of ‘The Invite’

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Priyanka Chopra brings the colors of Sylvia Cherassi to Cannes Lions 2026

Aooo Talk Road to second album “Rooom”: Interview

Katei announces the latest information on Manon’s hiatus, warns against making assumptions

Outfits, emotes, and jam tracks

Trending Posts

Priyanka Chopra brings the colors of Sylvia Cherassi to Cannes Lions 2026

June 25, 2026

Aooo Talk Road to second album “Rooom”: Interview

June 25, 2026

Katei announces the latest information on Manon’s hiatus, warns against making assumptions

June 25, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.