Pakistan-Linked APT36 Floods Indian Govt Networks With AI-Made ‘Vibeware’

2026-03-05T20:51:43Z5544ea4d44ac90eaaf0c705fb0371dd6dcc08861d5882fb501c8901a928fca8d
1Password2FA phishingAI-generated malwareAPT36Comet AIEuropolGoogle SheetsLeakBaseMFA bypassPerplexityPleaseFixRMMTrustConnect Software PTY LTDTycooncalendar invitecloud abusecredential theftlaw enforcementphishingphishing-as-a-servicestolen certificatesvibewarezero-click

What happened

Multiple high-risk campaigns and disclosures: Bitdefender attributes AI-generated ‘vibeware’ attacks to Pakistan-linked APT36 targeting Indian government officials and abusing trusted cloud services (Google Sheets) for credential theft and persistence. Zenity Labs disclosed PleaseFix flaws in Perplexity’s Comet/Comet AI browser that enable zero-click calendar-invite attacks allowing AI agents to exfiltrate 1Password credentials and personal files. A phishing campaign used stolen TrustConnect certificates to sign malware impersonating Zoom/Teams updates and dropped RMM tools for persistent,priv

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
5544ea4d44ac90eaaf0c705fb0371dd6dcc08861d5882fb501c8901a928fca8d
Enrichment time
2026-03-05T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Pakistan-Linked APT36 Floods Indian Govt Networks With AI-Made ‘Vibeware’ · Baitaphish