Fake APT36 ransomware locks screens but encrypts nothing

Published

The screen said "pakistanware by APT36", the wallpaper switched to a Pakistani flag, and a ransom note appeared. None of the victim's files had been encrypted. Harihara Sudhan of K7 Labs has traced the incident back to a pirated Windows activation tool, and concludes that the nation-state branding on the payload does not hold up.

The more useful finding sits underneath the theatrics. K7 says its analysis of critical incidents over several years shows KMS Auto, an unauthorised activator for Microsoft products, frequently present on compromised endpoints, particularly in ransomware cases. The company is careful to say it could not prove KMS Auto was the entry point every time. In this case it was the earliest observable event.

A cracked activator, then a miner, then two remote tools

The intrusion unfolded over several days rather than all at once. After KMS Auto ran, K7's telemetry showed the XMRig cryptocurrency miner deployed on the machine. Several hours later ScreenConnect, a legitimate remote support product, was installed from folders under C:\ProgramData named HvHosts and OneDriveServer. MeshAgent followed, which K7 reads as a second backdoor in case the first was found. The company observed a consistent 12 to 24 hour interval between stages.

Each of those tools has a legitimate use, which is the point K7 makes: in isolation they look like low-severity anomalies, but in sequence and close together they amount to a deliberate compromise.

A ransom note with no way to pay

The final payload, named SecurityHealthServices.exe to pass as a Windows Defender process, carries metadata reading "APT36 Transparent Tribe Pakistanware" and a Pakistani flag as its icon. It drops into the all-users Startup folder, changes the wallpaper, and pins an overlay above every other window to convince the victim their data is locked.

K7 found no encryption code or activity. The malware appends an extra .exe to executable files, leaving double extensions, creates Run, RunOnce and Startup entries, hides copies of itself in AppData with a super hidden attribute, and stages scripts and binaries in C:\Users\Public\Recovery. Its RECOVERY_README.txt contains no wallet address, no ransom amount, no deadline and no contact method. That makes it scareware: the goal is fear, not cryptography.

Is it really Transparent Tribe?

Transparent Tribe, also known as APT36, is a Pakistani state-aligned espionage group active since roughly 2013 that goes after strategic, military and diplomatic targets, most recently with a USB tool built to cross air gaps. K7 finds the evidence for its involvement here inconclusive: no targeted attack on an organisation and no data theft was observed, and espionage groups do not usually announce themselves with flags. The company's assessment is that the activity looks more like a hoax or a minor prank than a deliberate APT operation. A self-applied label is not attribution, and IntelFusions does not treat this as a Transparent Tribe operation.

Treat KMS Auto as a hacking tool

K7 says it will now classify KMS Auto as a HackTool. Defenders can draw the same line: flag activator executions, particularly from unusual folders or with unexpected child processes, and alert on remote management tools such as ScreenConnect or MeshAgent that nobody in IT deployed. Any ransomware screen should be checked against what has actually happened to the files before anyone reaches for a backup or a negotiator.

Indicators (MD5)

The fake ransomware is the part that makes the headline, but the free activator is the part that did the damage. A pirated tool quietly handed the machine over days before anyone saw a flag, and the same kind of software has been used as a delivery route by far more serious actors.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Detection coverage

Read the full analysis on IntelFusions