Cyber Warfare During Operation Sindoor: Malware Campaign Analysis and Detection Framework
Prakhar Paliwal, Atul Kabra, and Manjesh Kumar Hanawal
Indian Institute of Technology Bombay, Mumbai, Maharashtra
Operation Sindoor, originally a military response to the terrorist attack in Pahalgam on April 22, 2025, swiftly evolved into a sophisticated cyber campaign orchestrated by Advanced Persistent Threat (APT) group APT36, also known as Transparent Tribe, capitalizing on the incident’s geopolitical significance. Telemetry data, identified anomalous spear-phishing traffic targeting Indian governmental and defence networks commencing April 17, 2025,
five days prior to the attack, suggesting preemptive reconnaissance activities. By April 24, 2025, malicious documents exploiting the Pahalgam attack, such as “Action Points & Response by Govt Regarding Pahalgam Terror Attack.pdf” (authored under the pseudonym “Kalu Badshah”), proliferated across public domains, hosted on fraudulent websites including jkpolice[.]gov[.]in[.]kashmirattack[.]exposed and pahalgamattack[.]com .
These domains, registered within 48 hours post-attack and hosted across autonomous systems such as AS 200019 (Alexhost Srl) and AS 213373 (IP Connect Inc), impersonated reputable Indian entities, notably the Jammu & Kashmir Police and Indian Air Force, to facilitate credential harvesting and surreptitious data exfiltration.
Table 1: Compilation of Documents
| S. No. | Document | Format |
|---|
| 1 | Report & Update Regarding Pahalgam Terror Attack | PDF |
|---|
| 2 | Report Update Regarding Pahalgam Terror Attack | PDF |
|---|
| 3 | Action Points & Response by Govt Regarding Pahalgam Terror Attack | PDF |
|---|
| 4 | J&K Police Letter | PDF |
|---|
| 5 | ROD on Review Meeting held on 10 Apr 2025 by Secy DRDO | PDF |
|---|
| 6 | Record of Discussion – Technical Review Meeting Notice | PDF |
|---|
| 7 | Meeting Notice – 13th JWG meeting (India – Nepal) | PDF |
|---|
| 8 | Agenda Points for Joint Venture Meeting at IHQ MoD | PDF |
|---|
| 9 | DO Letter, Integrated HQ of MoD | PDF |
|---|
| 10 | Collegiate Meeting Notice & Action Points – MoD | PDF |
|---|
| 11 | Letter to the Raksha Mantri Office | PDF |
|---|
| 12 | (Unnamed file “pdf”) | PDF |
|---|
| 13 | Alleged Case of Sexual Harassment by Senior Army Officer | PDF |
|---|
| 14 | Agenda Points of Meeting of Dept of Defence | HTML |
|---|
| 15 | Action Points of Meeting of Dept of Defence | HTML |
|---|
| 16 | Agenda Points of Meeting of External Affairs Dept | HTML |
|---|
Table 2: Phishing Domains and Associated IP Addresses
| S. No. | Domain Name | IP Address(es) |
|---|
| 1 | jkpolice[.]gov[.]in[.]kashmirattack[.]exposed | 37.221.64.134, 78.40.143.189 |
|---|
| 2 | iaf[.]nic[.]in[.]ministryofdefenceindia[.]org | 37.221.64.134 |
|---|
| 3 | email[.]gov[.]in[.]ministryofdefenceindia[.]org | 45.141.58.224 |
|---|
| 4 | email[.]gov[.]in[.]departmentofdefenceindia[.]link | 45.141.59.167 |
|---|
| 5 | email[.]gov[.]in[.]departmentofdefence[.]de | 45.141.58.224 |
|---|
| 6 | email[.]gov[.]in[.]briefcases[.]email | 45.141.58.224, 78.40.143.98 |
|---|
| 7 | email[.]gov[.]in[.]modindia[.]link | 84.54.51.12 |
|---|
| 8 | email[.]gov[.]in[.]defenceindia[.]ltd | 45.141.58.224, 45.141.58.33 |
|---|
| 9 | email[.]gov[.]in[.]indiadefencedepartment[.]link | 45.141.59.167 |
|---|
| 10 | email[.]gov[.]in[.]departmentofspace[.]info | 45.141.58.224 |
|---|
| 11 | email[.]gov[.]in[.]indiangov[.]download | 45.141.58.33, 78.40.143.98 |
|---|
| 12 | indianarmy[.]nic[.]in[.]departmentofdefence[.]de | 176.65.143.215 |
|---|
| 13 | indianarmy[.]nic[.]in[.]ministryofdefenceindia[.]org | 176.65.143.215 |
|---|
| 14 | email[.]gov[.]in[.]indiandefence[.]work | 45.141.59.72 |
|---|
| 15 | email[.]gov[.]in[.]drdosurvey[.]info | 192.64.118.76 |
|---|
APT36, also known as Transparent Tribe, is a
Pakistan-based advanced persistent threat (APT) group active since at least 2013. The group is widely attributed to Pakistani state interests and is primarily focused on cyber espionage against the Indian government organizations, military, defense contractors, research centers, diplomats, and critical infrastructure. APT36 is also known by aliases such as Project M, Mythic Leopard, Earth Karkaddan, and others.