ESET reported that the DoNot Team resumed development of its Android malware after a period of inactivity, releasing a new spyware family called DoNot Go that appears to replace the older Hornbill implant. The malware was distributed through fake or trojanized applications and was linked to a threat actor long associated with espionage activity targeting South Asia, particularly users in India and Pakistan.
The updated implant expanded surveillance capabilities on Android devices, including collecting files, harvesting contact and SMS data, tracking call logs and device location, recording audio, and exfiltrating information to attacker-controlled infrastructure. Researchers said the campaign showed continued operational investment by the group and reflected an effort to modernize its mobile espionage tooling rather than abandon it.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
ESET publicly released a report titled 'DoNot Go! Do not respawn!' describing its findings on the DoNot threat group's activity. The publication marks the disclosure of the research covered by the reference.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.