DoNot, also tracked as APT-C-35, is a suspected South Asian cyber-espionage threat actor known for targeted spear-phishing campaigns against government, military, and defense-related entities. The actor has used document-themed lures tailored to specific regional targets, including military-themed decoys, to obtain initial access. In one documented operation targeting Bangladesh’s military and defense establishment, DoNot used a spear-phishing RTF lure with remote template injection and selective delivery controls to provide malicious content only to intended victims. DoNot commonly employs staged malware delivery chains. Observed tradecraft includes malicious VBA macros, architecture-aware shellcode, dynamic API resolution, anti-hooking checks, multi-stage XOR decoding, and modular payload retrieval disguised as benign file types. Later-stage implants have used DLL execution through rundll32, host profiling, encrypted command-and-control communications over HTTPS, and scheduled-task persistence masquerading as legitimate system activity. The malware family associated with these operations has also used AES-128-CBC-protected configuration and beaconing, along with structured tasking workflows for reconnaissance and follow-on payload delivery. Attribution to DoNot is supported by consistent command-and-control URI patterns, matching protocol parameters and beacon formats, shared multi-stage loader architecture, and identical cryptographic material observed across independently documented samples. The actor’s activity in this case aligns with an espionage mission focused on collecting information from defense-sector targets rather than financially motivated disruption or extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.