DoNot APT Expands Reach: Targeting European Foreign Ministries with LoptikMod Malware

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Targeted Malware Attacks: Unraveling the DoNot Team’s Threat Landscape

Overview of the Threat

A recent cybersecurity investigation has unearthed a concerning trend: a threat actor believed to be linked to India is targeting a European foreign affairs ministry. This campaign employs sophisticated malware designed to extract sensitive information from compromised systems. The threat has been linked to an advanced persistent threat (APT) group known as the DoNot Team, recognized in various circles as APT-C-35, Mint Tempest, Origami Elephant, SECTOR02, and Viceroy Tiger. This group has been active since 2016, making their operations a notable concern for cybersecurity experts.

The Nature of the DoNot Team’s Attacks

According to the Trellix Advanced Research Center, the DoNot Team is notorious for its use of custom-built Windows malware. These tools often include backdoors such as YTY and GEdit, which are delivered through targeted spear-phishing emails or malicious documents. The overarching focus of the group’s activities has generally centered on entities like government institutions, defense organizations, and non-governmental organizations (NGOs), particularly in South Asia and Europe.

The Attack Chain: From Phishing to Compromise

The methodology employed by the DoNot Team is both calculated and methodical. The attack typically begins with phishing emails aimed at deceiving recipients into clicking on a seemingly innocuous Google Drive link. This action triggers the download of a RAR archive, eventually leading to the deployment of malware named LoptikMod. The use of LoptikMod has been exclusively associated with this group since at least 2018, further indicating their persistence and strategic planning.

Details of the Phishing Attempt

The phishing emails in question are often disguised as communications from defense officials, featuring subject lines that cleverly relate to specific events, such as visits from international defense officials. In one recent instance, an email mentioned the Italian Defense Attaché’s visit to Dhaka, Bangladesh.

Trellix analysts have noted that the emails are carefully structured, utilizing HTML formatting with UTF-8 encoding to ensure that special characters—like ‘é’ in "Attaché"—are displayed correctly. This attention to detail increases the likelihood that the recipient will engage with the email, thereby enhancing the effectiveness of the phishing attempt.

Payload Delivery: The Execution of LoptikMod

Once the RAR archive is downloaded, it contains a malicious executable masquerading as a PDF. Opening this file activates the LoptikMod remote access trojan, which is capable of establishing persistent access to the host system through scheduled tasks. The malware can connect to a remote server, allowing it to send system information, receive further instructions, download additional modules, and exfiltrate data.

Advanced Evasion Tactics

The sophistication of this malware is underscored by its implementation of anti-virtual machine (VM) techniques and ASCII obfuscation. These methods complicate the malware’s execution within virtual environments and assist in evading detection, making it increasingly difficult for security analysts to ascertain its purpose. Additionally, the malware is designed to ensure that only one instance runs on a compromised device, thereby minimizing the risk of interference from other processes or security measures.

Command and Control Infrastructure

Trellix has observed that the command-and-control (C2) server employed in this campaign is currently inactive. This inactivity raises questions about whether the infrastructure has been disabled, is undergoing maintenance, or if the threat actors have transitioned to a new server. The implications are significant; without operational C2 infrastructure, determining the exact commands sent to infected endpoints and the data collected from them becomes virtually impossible.

The Cyber Espionage Motive

Experts from Trellix emphasize that the group’s operational patterns—characterized by extensive surveillance and meticulous data extraction—suggest a notable cyber espionage agenda. Although their historical focus has primarily been on South Asian targets, the recent intrusion into European diplomatic communications indicates a marked shift in their strategic objectives.

This evolving threat landscape underscores the importance of vigilance among government entities and organizations within affected regions, reinforcing the need for robust cybersecurity measures to fend off such sophisticated attacks.


The increasing complexity and adaptability of groups like the DoNot Team illustrate the ongoing challenges in cybersecurity and the necessity of proactive measures to safeguard sensitive information.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Finnish Appeals Court Revives Prosecution of Eagle S Officers for Subsea Cable Damage

A Finnish appeals court has revived the prosecution of three senior officers of the Eagle S, a Russia-linked oil tanker, for severing multiple subsea...

OpenAI’s Postmortem Reveals Gaps in Security Oversight Before Hugging Face Hack

Security Oversight Gaps Identified in OpenAI's Postmortem OpenAI's recent postmortem regarding the Hugging Face hack has revealed significant lapses in security oversight prior to the...

Veeam to Showcase Cyber Recovery and AI Solutions at LEAP 2026 in Saudi Arabia

Veeam is set to showcase its advanced cyber recovery and artificial intelligence solutions at LEAP 2026 in Saudi Arabia, marking its sixth consecutive year...

TeamViewer security advisory AV26-852 warns of vulnerabilities across multiple products

Advisory Number: AV26-852 Date: August 26, 2026 TeamViewer Vulnerabilities Identified As of August 26, 2026, TeamViewer has reported vulnerabilities affecting several of its products. The affected software...