Pakistan's DeskRAT Spyware: How Regional Crises Fuel Cyber Attacks on India

Indian intelligence agencies have detected a sophisticated cyber espionage campaign targeting government and military systems. Pakistan-based hacking group Transparent Tribe is using DeskRAT spyware that specifically targets Boss Linux operating systems used in Indian offices. The hackers strategically time their attacks during regional crises when security agencies are under maximum stress. This stealthy spyware remains undetected for weeks while monitoring systems and extracting sensitive operational documents.

Key Points: Pakistan Transparent Tribe DeskRAT Spyware Targets Indian Systems

  • Hackers target Indian systems during regional crises like Sri Lanka protests
  • DeskRAT spyware specifically targets Boss Linux government systems
  • Transparent Tribe group sends urgent emails with malicious attachments
  • Spyware remains undetected for weeks while extracting sensitive documents
3 min read

Pakistan targets systems amid regional crises; Indian agencies smell a 'DeskRAT'

Indian agencies detect Pakistan's DeskRAT spyware targeting military and government systems during regional crises. Learn how hackers exploit stress periods for cyber espionage.

"The most lethal aspect of DeskRAT is that it is not designed to crash a system, but to monitor it - Intelligence Officer"

New Delhi, Nov 8

At the start of 2025, following a high-level meeting in the national Capital, Indian Intelligence agencies had signalled that going into the future, New Delhi's major concerns on the security front would be cybercrime. While cybercrime has always been a threat to the security of the nation, the agencies have smelt a DeskRAT and have been picking up a new trend.

Hackers from Pakistan, China and other countries have ramped up operations and have been targeting both financial institutions and the military. This is part of the psy-ops that Pakistan has launched and the larger aim is to embarrass the military and hurt the Indian economy.

The Indian agencies have been picking up a new trend in the manner that these criminals have been operating.

The change in trend was noticed when the protests broke out in Sri Lanka. When a neighbouring nation is in trouble there is always a high alert. The stress the security agencies go through at that time is what the hackers are taking advantage of. At such a time, the hackers are aware that some officers can make a mistake by opening up emails that are marked 'urgent'.

These emails marked 'urgent' contain files which once opened can take over the system. Once these attachments are opened, then the hackers get to withdraw operational documents, and strategic plans. There are times when such a spyware sits in the system for weeks. Until it is detected the hackers have complete access to the system.

The same modus operandi was used when protests broke out in Bangladesh and then Nepal. Investigations revealed that these operations are carried out using a spyware called DeskRAT. Further, the recent incidents have been traced to a Pakistan-based group called Transparent Tribe.

The spyware has been designed in such a way that it specifically targets the Boss Linux systems. These operating systems are widely used in Indian government offices. Further the spyware operates with stealth, thus making detection very difficult. Until the time it is detected, it browses government documents, extracts sensitive information and also monitors activity.

Even in the aftermath of the Pahalgam terror attack, this group was very active. It sent out emotionally charged mails and messages to government officials. Many opened these attachments, following which the hacking group gained access to their systems.

Several agencies are working overtime to find a solution to this latest spyware. An officer explained that the most lethal aspect of this spyware, DeskRAT is that it is not designed to crash a system, but to monitor it. This makes the detection extremely challenging and hence the spyware remains in the system for longer durations. This indicates that the hacking group is focussed not on disruption, but on long term spying.

Intelligence officials say that DeskRAT is one of the most lethal spywares that has been introduced into the Indian systems in a long time. The sophistication is what is making it hard to detect. Without anyone getting wind of its existence, it manages to do the damage. It collects information and also disrupts communication channels within the military and other government offices.

This group gets active at a time when there are disturbances in India's neighbourhood or within the country. There is a lot of stress to ensure that such violence does not spill over into India. This is the time the hackers strike taking advantage of the stress within the system. Transparent Tribe had deployed DeskRAT into the Indian systems even when protests had broken out in Ladakh recently.

- IANS

Share this article:

Reader Comments

P
Priya S
The timing of these attacks during regional crises shows how calculated these operations are. Our agencies need to be two steps ahead. Hope they develop countermeasures soon! 🙏
R
Rohit P
Why are we still using Boss Linux if it's so vulnerable? Shouldn't we migrate to more secure systems? This feels like basic cybersecurity hygiene that's being ignored. 😕
S
Sarah B
As someone working in IT security, I can say DeskRAT sounds sophisticated. The fact that it focuses on long-term monitoring rather than disruption makes it particularly dangerous. Regular security audits are crucial.
V
Vikram M
This is a wake-up call for digital India. We're becoming increasingly dependent on technology but our security measures aren't keeping pace. Jai Hind! 🚨
M
Michael C
While I understand the concern about foreign threats, we also need better internal protocols. Government employees should receive mandatory cybersecurity training - many breaches happen due to human error.
A
Ananya R
The pattern is clear - they strike when we're distracted by regional issues. Our intelligence agencies need to anticipate these moves and strengthen defenses proactively. Proud of our cyber warriors working overtime! 💪

We welcome thoughtful discussions from our readers. Please keep comments respectful and on-topic.

Leave a Comment

Minimum 50 characters 0/50