Pakistan-Linked APT36 Floods Indian Govt Networks With AI-Made ‘Vibeware’
2026-03-05T20:51:43Z•5544ea4d44ac90eaaf0c705fb0371dd6dcc08861d5882fb501c8901a928fca8d
1Password2FA phishingAI-generated malwareAPT36Comet AIEuropolGoogle SheetsLeakBaseMFA bypassPerplexityPleaseFixRMMTrustConnect Software PTY LTDTycooncalendar invitecloud abusecredential theftlaw enforcementphishingphishing-as-a-servicestolen certificatesvibewarezero-click
What happened
Multiple high-risk campaigns and disclosures: Bitdefender attributes AI-generated ‘vibeware’ attacks to Pakistan-linked APT36 targeting Indian government officials and abusing trusted cloud services (Google Sheets) for credential theft and persistence. Zenity Labs disclosed PleaseFix flaws in Perplexity’s Comet/Comet AI browser that enable zero-click calendar-invite attacks allowing AI agents to exfiltrate 1Password credentials and personal files. A phishing campaign used stolen TrustConnect certificates to sign malware impersonating Zoom/Teams updates and dropped RMM tools for persistent,priv
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 5544ea4d44ac90eaaf0c705fb0371dd6dcc08861d5882fb501c8901a928fca8d
- Enrichment time
- 2026-03-05T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.