The #APT36 cluster can't stop, won't stop
They just added #CVE-2026-21509 and #CVE-2026-21513 (borrowed from APT28) onto their delivery chain, pushing updated FIREPOWER via weaponized RTF and LNKs against 🇮🇳 targets. Separately, fresh SheetCreep + a shiny new CrystalShell-Slack variant co-dropped on a Kashmir target, because one implant is never enough. The vibeware factory is running three shifts: Crystal, .NET and PowerShell.
Pulse ID: 6a3add255a93c4e851962479
Pulse Link: https://otx.alienvault.com/pulse/6a3add255a93c4e851962479
Pulse Author: AlienVault
Created: 2026-06-23 19:23:16
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT28 #CyberSecurity #InfoSec #LNK #NET #OTX #OpenThreatExchange #PowerShell #RAT #RTF #bot #AlienVault


