The advanced persistent threat group known as DONOT Team has been discovered leveraging two nearly identical Android applications to conduct sophisticated intelligence-gathering operations targeting specific individuals and groups within India.
Cybersecurity researchers at Cyfirma have uncovered the malicious "Tanzeem" and "Tanzeem Update" applications, which purport to be chat applications but are designed to covertly harvest sensitive information from compromised devices. The apps, whose name translates to "organization" in Urdu, appear strategically crafted to target individuals of national security interest.
When users install these applications, they are prompted to enable accessibility features and grant extensive permissions. The apps then proceed to shut down while stealthily collecting critical device information. The malicious software can read call logs, access contacts, retrieve SMS messages, monitor precise device locations, and extract account information.
A notable technical aspect of these applications is their use of OneSignal, a legitimate customer engagement platform, to send push notifications. This technique allows the threat actors to potentially deploy additional malicious payloads and maintain persistent access to compromised devices.
The DONOT Team, also tracked under various aliases like APT-C-35 and Viceroy Tiger, has a history of conducting cyber espionage campaigns across South Asia. Their operations have consistently targeted organizations and individuals in countries like Pakistan, Sri Lanka, and Bangladesh.
Researchers noted that the group's tactics demonstrate an evolving approach to intelligence gathering, with a focus on strategic data collection that could potentially support national interests. The use of seemingly innocuous applications and legitimate platforms highlights the sophisticated methods employed by this threat actor.
Cybersecurity experts recommend users exercise extreme caution when downloading applications, particularly those from unknown sources, and maintain updated security protocols to mitigate such sophisticated threats.
Found this article interesting? Keep visit thesecmaster.com, and our social media page on Facebook, LinkedIn, Twitter, Telegram, Tumblr, Medium, and Instagram and subscribe to receive tips like this.
You may also like these articles: Here are the 5 most contextually relevant blog posts:
North Korean Hackers Embed Malware in macOS Flutter Apps, Targets Cryptocurrency Users
Charming Kitten Deploys New C++ BellaCiao Malware Variant in Cyber Espionage Campaign
North Korean Hackers Deploy New OtterCookie Malware Targeting Software Developers
North Korean Hackers Steal $308 Million from DMM Bitcoin Exchange
AppLite Banking Trojan Targets Job Seekers Through Malicious Phishing Emails
Anthony Denis a Security News Reporter with a Bachelor's in Business Computer Application. Drawing from a decade of digital media marketing experience and two years of freelance writing, he brings technical expertise to cybersecurity journalism. His background in IT, content creation, and social media management enables him to deliver complex security topics with clarity and insight.
“Knowledge Arsenal: Empowering Your Security Journey through Continuous Learning”
"Cybersecurity All-in-One For Dummies" offers a comprehensive guide to securing personal and business digital assets from cyber threats, with actionable insights from industry experts.
BurpGPT is a cutting-edge Burp Suite extension that harnesses the power of OpenAI's language models to revolutionize web application security testing. With customizable prompts and advanced AI capabilities, BurpGPT enables security professionals to uncover bespoke vulnerabilities, streamline assessments, and stay ahead of evolving threats.
PentestGPT, developed by Gelei Deng and team, revolutionizes penetration testing by harnessing AI power. Leveraging OpenAI's GPT-4, it automates and streamlines the process, making it efficient and accessible. With advanced features and interactive guidance, PentestGPT empowers testers to identify vulnerabilities effectively, representing a significant leap in cybersecurity.
Tenable BurpGPT is a powerful Burp Suite extension that leverages OpenAI's advanced language models to analyze HTTP traffic and identify potential security risks. By automating vulnerability detection and providing AI-generated insights, BurpGPT dramatically reduces manual testing efforts for security researchers, developers, and pentesters.
Microsoft Security Copilot is a revolutionary AI-powered security solution that empowers cybersecurity professionals to identify and address potential breaches effectively. By harnessing advanced technologies like OpenAI's GPT-4 and Microsoft's extensive threat intelligence, Security Copilot streamlines threat detection and response, enabling defenders to operate at machine speed and scale.