DiscoverCYFIRMA ResearchCYFIRMA Research- Android Malware in DONOT APT Operations
CYFIRMA Research- Android Malware in DONOT APT Operations

CYFIRMA Research- Android Malware in DONOT APT Operations

Update: 2025-01-22
Share

Description

The CYFIRMA team has analyzed malware linked to the Indian APT group DONOT, uncovering its use of a deceptive app called “Tanzeem” to gather intelligence under the guise of a chat platform. The app shuts down after permissions are granted, suggesting a targeted approach. Two analyzed versions, from October and December, showed minimal differences, indicating consistent tactics. The misuse of the OneSignal platform, typically for legitimate notifications, to deliver phishing links highlights the group’s evolving methods to maintain persistence. These findings emphasize the need to understand such threats as the group continues adapting to target individuals across the region. Read the full analysis for more details.
 
Link to the Research Report: https://www.cyfirma.com/research/android-malware-in-donot-apt-operations/

 #CyberSecurity #APTGroup #ThreatIntelligence #donotapt #aptdonot #internalthreat #CYFIRMA #tanzeem #OneSignal #androidmalware #malware #CyfirmaResearch #ExternalThreatLandscapeManagement #ETLM

https://www.cyfirma.com/

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

CYFIRMA Research- Android Malware in DONOT APT Operations

CYFIRMA Research- Android Malware in DONOT APT Operations

CYFIRMA