Targeted Malware Attacks: Unraveling the DoNot Team’s Threat Landscape
Overview of the Threat
A recent cybersecurity investigation has unearthed a concerning trend: a threat actor believed to be linked to India is targeting a European foreign affairs ministry. This campaign employs sophisticated malware designed to extract sensitive information from compromised systems. The threat has been linked to an advanced persistent threat (APT) group known as the DoNot Team, recognized in various circles as APT-C-35, Mint Tempest, Origami Elephant, SECTOR02, and Viceroy Tiger. This group has been active since 2016, making their operations a notable concern for cybersecurity experts.
The Nature of the DoNot Team’s Attacks
According to the Trellix Advanced Research Center, the DoNot Team is notorious for its use of custom-built Windows malware. These tools often include backdoors such as YTY and GEdit, which are delivered through targeted spear-phishing emails or malicious documents. The overarching focus of the group’s activities has generally centered on entities like government institutions, defense organizations, and non-governmental organizations (NGOs), particularly in South Asia and Europe.
The Attack Chain: From Phishing to Compromise
The methodology employed by the DoNot Team is both calculated and methodical. The attack typically begins with phishing emails aimed at deceiving recipients into clicking on a seemingly innocuous Google Drive link. This action triggers the download of a RAR archive, eventually leading to the deployment of malware named LoptikMod. The use of LoptikMod has been exclusively associated with this group since at least 2018, further indicating their persistence and strategic planning.
Details of the Phishing Attempt
The phishing emails in question are often disguised as communications from defense officials, featuring subject lines that cleverly relate to specific events, such as visits from international defense officials. In one recent instance, an email mentioned the Italian Defense Attaché’s visit to Dhaka, Bangladesh.
Trellix analysts have noted that the emails are carefully structured, utilizing HTML formatting with UTF-8 encoding to ensure that special characters—like ‘é’ in "Attaché"—are displayed correctly. This attention to detail increases the likelihood that the recipient will engage with the email, thereby enhancing the effectiveness of the phishing attempt.
Payload Delivery: The Execution of LoptikMod
Once the RAR archive is downloaded, it contains a malicious executable masquerading as a PDF. Opening this file activates the LoptikMod remote access trojan, which is capable of establishing persistent access to the host system through scheduled tasks. The malware can connect to a remote server, allowing it to send system information, receive further instructions, download additional modules, and exfiltrate data.
Advanced Evasion Tactics
The sophistication of this malware is underscored by its implementation of anti-virtual machine (VM) techniques and ASCII obfuscation. These methods complicate the malware’s execution within virtual environments and assist in evading detection, making it increasingly difficult for security analysts to ascertain its purpose. Additionally, the malware is designed to ensure that only one instance runs on a compromised device, thereby minimizing the risk of interference from other processes or security measures.
Command and Control Infrastructure
Trellix has observed that the command-and-control (C2) server employed in this campaign is currently inactive. This inactivity raises questions about whether the infrastructure has been disabled, is undergoing maintenance, or if the threat actors have transitioned to a new server. The implications are significant; without operational C2 infrastructure, determining the exact commands sent to infected endpoints and the data collected from them becomes virtually impossible.
The Cyber Espionage Motive
Experts from Trellix emphasize that the group’s operational patterns—characterized by extensive surveillance and meticulous data extraction—suggest a notable cyber espionage agenda. Although their historical focus has primarily been on South Asian targets, the recent intrusion into European diplomatic communications indicates a marked shift in their strategic objectives.
This evolving threat landscape underscores the importance of vigilance among government entities and organizations within affected regions, reinforcing the need for robust cybersecurity measures to fend off such sophisticated attacks.
The increasing complexity and adaptability of groups like the DoNot Team illustrate the ongoing challenges in cybersecurity and the necessity of proactive measures to safeguard sensitive information.


