In the lead-up to APNIC60, where Chief Technical Officer Leslie Daigle will give a keynote address, we’re publishing a series of articles that address regionally meaningful threats beyond the well-documented Chinese-origin attacks. We present four distinct Asia-linked campaigns based on attacks seen directly in AIDE or confirmed by matching public reports. Each case offers a different lens on the threat landscape—ranging from geopolitical motivations to financial disruption and targeted espionage. Our goal is to provide context, elevate regional perspectives, and set the stage for deeper discussion during the keynote.
Introduction
Advanced persistent threat (APT) groups are increasingly turning to legitimate telecommunications infrastructure to hide operations in plain sight. One such campaign involves APT36 (Transparent Tribe), a believed Pakistani state-aligned group that systematically exploits Internet service provider networks to launch cyber operations against Indian targets.
APT36 has been active since at least 2013, but its operations surged in 2025, when external reports of intensified activity surfaced and were subsequently confirmed in AIDE data. AIDE, GCA’s global honeypot platform spanning 25 countries with ~200 sensors and supporting SSH, Telnet, FTP, HTTP/HTTPS, and SMTP, has run on GCA’s ProxyPot technology since November 2024.
Between April and August 2025, AIDE captured 116,374 incidents on Indian sensors across 75 Autonomous System Numbers (ASNs) based in Pakistan.
The findings show how APT36 abused ISP infrastructure, deployed multi-architecture malware, and exploited routing security gaps at scale. By abusing telecom infrastructure and taking advantage of weak routing security, groups like APT36 can launch massive, cross-border campaigns that undermine trust in critical networks, disrupt economies, and escalate geopolitical tensions. What happens inside ISP and backbone provider networks has real-world consequences: hospitals, schools, businesses, and governments all rely on these networks for daily operations. Strengthening routing security and closing systemic gaps is therefore not just a technical exercise—it’s a matter of national security, regional stability, and protecting the everyday functioning of the Internet.
Key Findings
- APT36 escalation: Active since 2013, surged in 2025 via Pakistan-based infrastructure
- Scale of activity: Recorded 116,374 incidents across 75 ASNs; peak 26,000/day (April 30)
- Telecom exploitation: 61.2 percent from ISPs, 37.6 percent from Network Service Providers (NSPs); top ASNs: Pace Telecom, Multinet, NTC
- Malware sophistication: 379 BusyBox commands, 338 binary injections, multi-architecture dvrHelper agents
- Routing security gaps: 98.7 percent IRR issues, 98.7 percent RPKI failures, 98.7 percent bogon/leaks, 9.2 percent MANRS participation
Surge in Attacks
APT36 activity spiked dramatically in late April. On April 30, AIDE sensors in India recorded more than 26,000 attacks in a single day originating from Pakistan-based networks — nearly 10 times above baseline traffic. The surge closely paralleled geopolitical tensions, suggesting coordinated escalation.

Exploiting Telecom Infrastructure
APT36 activity was widely distributed across Pakistan’s backbone providers. In total, attacks spanned 75 ASNs, with top contributors (in the peak window) including:
| ASN | Organization | Attack Volume |
|---|---|---|
| AS A | Organization 1 | 33,238 |
| AS B | Organization 2 | 25,817 |
| AS C | Organization 3 | 25,469 |
The broader distribution reflected:
- 61.2 percent of attacks originating from Cable/DSL/ISP providers
- 37.6 percent from Network Service Providers (NSPs)
- 1.1 percent from Educational/Research networks
- <0.1 percent each from Content, Enterprise, and other network service providers

Technical Tactics
APT36 combined persistent brute-force attempts with malware tailored for IoT-rich environments.
- Credential harvesting: Brute-force campaigns against routers, DVRs, and cameras
- Malware deployment: Binary loaders and self-propagating dvrHelper agents
- Cross-architecture propagation: Payloads compiled for multiple CPU architectures to expand reach
- Redundant C2 infrastructure: Simultaneous use of HTTP, TFTP, and FTP, with malware embedded across multiple directories
Multi-Architecture Malware Deployment
In particular, payload analysis identified 379 unique BusyBox command executions, 338 distinct binary injection attempts, and deployment of self-replicating dvrHelper agents. Payloads were compiled for ARM, MIPS, and x86 architectures to ensure broad IoT device coverage.
Routing Security Gaps
Routing security deficiencies further amplified the campaign’s impact. Our analysis of MANRS metrics across the 75 targeted ASNs revealed near-universal weaknesses (any value above zero counted as affected):
- 98.7 percent had unregistered or outdated IRR entries
- 98.7 percent failed RPKI validation
- 98.7 percent experienced bogon or route-leak incidents
- Only 9.2 percent were MANRS participants

Taken together, these findings illustrate how APT36 weaponized both IoT devices and telecom infrastructure. The campaign was motivated by espionage and disruption, carried out through credential harvesting, malware deployment, and botnet persistence, and sustained by systemic weaknesses in routing security.
For operators, this is not just about attribution. It is about ensuring their infrastructure is not repurposed for geopolitical conflicts.
Call to Action
The findings highlight how IP-, ASN-, and economy-level telemetry from AIDE and similar threat intelligence sources can provide early warning of infrastructure abuse campaigns. Operators and researchers can:
- Leverage AIDE or similar threat intelligence to track unwanted traffic patterns across IPs, ASNs, and economies, distinguishing baseline noise from coordinated abuse.
- Identify abused networks and collaborate with affected providers to mitigate malicious use of their infrastructure.
- Improve routing security by maintaining accurate IRR records, enforcing RPKI validation, and adopting MANRS best practices to close systemic gaps.
Even modest improvements in routing security would make it significantly harder for actors like APT36 to maintain deniable footholds across regional networks.
Conclusion
APT36’s abuse of telecommunications infrastructure in 2025 shows that weak routing security and gaps in ISP defenses are not just technical issues—they are serious vulnerabilities with wider consequences. The data demonstrates how adversaries can use the Internet’s core infrastructure to carry out operations that cross national borders.
AIDE’s honeypot network recorded not only isolated attacks but repeated exploitation of backbone providers that support South Asia’s Internet connectivity. When these providers are drawn into cross-border activity, the risks extend beyond single organizations and begin to affect regional stability and economic security.
Building a more resilient Internet will require joint effort. AIDE’s visibility at the IP, ASN, and economy level offers operators an early view of how their networks are being misused. Combining that visibility with better routing security and stronger information sharing between providers, governments, and researchers gives us the best chance to prevent this type of abuse in the future.
References
- The Evolution of Transparent Tribe’s New Malware
https://research.checkpoint.com/2024/the-evolution-of-transparent-tribes-new-malware/ - APT-36 Uses New TTPs and New Tools to Target Indian Governmental Organizations
https://www.zscaler.com/blogs/security-research/apt-36-uses-new-ttps-and-new-tools-target-indian-governmental-organizations - APT36: A Phishing Campaign Targeting Indian Government Entities
https://www.cyfirma.com/research/apt36-a-phishing-campaign-targeting-indian-government-entities/ - Dark Web Profile: APT36
https://socradar.io/dark-web-profile-apt36/ - APT Attackers Hiding in Plain Sight
https://www.darkreading.com/cyberattacks-data-breaches/apt-attackers-hiding-in-plain-sight - IC3 Cyber Safety Alert CSA 241216
https://www.ic3.gov/CSA/2024/241216.pdf



