Researchers linked DoNot APT (also tracked as APT-C-35 and Donot Team) to sustained cyberespionage campaigns against government, military, diplomatic, and foreign affairs targets, primarily in South Asia and later against a Southern European foreign ministry. Victims included organizations in Bangladesh, Sri Lanka, Pakistan, and Nepal, with lures themed around regional geopolitics such as Kashmir and diplomatic travel. In the European case, attackers used a spearphishing email impersonating defense officials and a Google Drive-hosted malicious RAR archive; earlier campaigns relied on malicious Office documents, remote-template injection, and compromised or spoofed email accounts to deliver malware aimed at collecting and exfiltrating sensitive data.
The group’s tooling evolved across both Windows and Android operations. Windows intrusions deployed malware families and frameworks including yty, Gedit, DarkMusical, and LoptikMod, using techniques such as DLL side-loading, encrypted payloads decrypted in memory, anti-VM and security-product checks, scheduled-task persistence, and HTTPS command-and-control through infrastructure including .buzz domains and totalservices[.]info. On Android, Cisco Talos described the Firestarter loader, which abused Google Firebase Cloud Messaging to receive payload URLs, gather identity and geolocation data, and selectively deliver follow-on spyware while maintaining resilience if primary C2 servers were disrupted.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
Trellix reported that the malware collected host information, encrypted it with AES, encoded it with Base64, and sent it via HTTP POST to totalservices[.]info. Based on server responses, it could download a follow-on payload named socker.dll and prepare additional persistence through a scheduled task named "MicorsoftVelocity."
Trellix found that executing notflog.exe created a mutex, dropped a batch file under %LocalAppdata%\TEMP\FROX\, and established persistence with a scheduled task named "PerformTaskMaintain" running every 10 minutes. The sample used obfuscation, runtime API loading, anti-VM checks, and code overlap that linked it to DoNot's LoptikMod malware family.
In the 2025 campaign, attackers sent a spear-phishing email from int.dte.afd.1@gmail[.]com with the subject "Italian Defence Attaché Visit to Dhaka, Bangladesh" and a Google Drive link. The link delivered a password-protected archive named SyClrLtr.rar containing the disguised executable notflog.exe.
Trellix documented a 2025 cyber-espionage campaign attributed to DoNot targeting a Southern European government entity in the diplomatic sector, described as a European foreign affairs ministry. The operation showed the group's interest expanding beyond its usual South Asian focus into European diplomatic targets.
K7 reported that a January 2023 sample in the campaign was named "Kashmir Solidarity Day Material .exe." This sample was part of the same DoNot activity cluster tied to .buzz command-and-control infrastructure.
K7 reported campaign samples spanning from September 2022 through January 2023 and linked them to DoNot infrastructure using .buzz domains registered through NameSilo and hosting associated with BitLaunch VPS services. The September 2022 campaign included a sample named "bodli.doc."
Talos reported that DoNot was using a newly discovered Android malware loader called Firestarter, which relied on Google Firebase Cloud Messaging to receive payload URLs and maintain operator control. The campaign targeted users and non-profit organizations associated with India, Pakistan, and the Kashmir region.
ESET said it monitored DoNot Team campaigns from September 2020 to October 2021 and observed spearphishing waves every two to four months. The operations targeted government, military, foreign affairs, and embassy entities in Bangladesh, Sri Lanka, Pakistan, and Nepal, including embassies abroad.
QiAnXin analyzed a recent Donot campaign using macro-enabled Office documents and remote-template injection documents that fetched Equation Editor exploit content, then downloaded loader DLLs and encrypted payloads. Researchers assessed the targeting included Sri Lanka and nearby regions, with persistence via startup links or scheduled tasks.
Multiple references state that DoNot APT, also tracked as APT-C-35, has been active since at least 2016. The group is described as targeting South Asian organizations with Windows and Android malware.
K7 observed DoNot changing its initial access technique from malicious Office documents to a ZIP archive named "Day .zip" containing a WinRAR SFX executable, a DLL, and Kashmir-themed decoy PDFs. The DLL created the mutex "olgui1pigg," attempted C2 contact, collected host data, and established persistence with a scheduled task running every four minutes.
ESET analyzed the yty malware variants Gedit and DarkMusical and reported that DarkMusical was used in campaigns targeting military organizations in Bangladesh and Nepal. The malware family was part of DoNot's Windows espionage toolset for data collection and exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 89 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcelabs.k7computing.com
Open sourceeset.com
Open sourceblog.talosintelligence.com
Open sourceti.qianxin.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.