created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: medium · affected_sectors: [] · au_impact: false
Transparent Tribe
Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0134 |
| Aliases | COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM |
| Attribution | Pakistan |
| Class | state |
| Active since | 2013 (per ATT&CK description) |
| ATT&CK entry created | 2021-09-02 |
| Techniques mapped | 19 |
Attribution — as claimed
Contested in ATT&CK's own wording (hedged, or two plausible sponsors).
Known TTPs
| Technique | Name |
|---|---|
T1027.013 |
Encrypted/Encoded File |
T1036.005 |
Match Legitimate Resource Name or Location |
T1059.005 |
Visual Basic |
T1189 |
Drive-by Compromise |
T1203 |
Exploitation for Client Execution |
T1204.001 |
Malicious Link |
T1204.002 |
Malicious File |
T1564.001 |
Hidden Files and Directories |
T1566.001 |
Spearphishing Attachment |
T1566.002 |
Spearphishing Link |
T1568 |
Dynamic Resolution |
T1583.001 |
Domains |
(First 12 of 19 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Ke3Chang — Pakistan-linked actor, same attribution class
- Apt28 — Pakistan-linked actor, same attribution class
- Apt29 — Pakistan-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0134 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.