logo

Esperts found new DoNot Team APT group’s Android malware

ID: c4251083-6c82-5801-bb2e-d420c7355390

STIX ID: report--c4251083-6c82-5801-bb2e-d420c7355390

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2025-01-20

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CYFIRMA researchers linked a new Android malware family named "Tanzeem" to the Indian APT group DoNot Team (APT‑C‑35/Origami Elephant). The malicious app masquerades as a chat client, requests Accessibility permissions, can exfiltrate call logs, contacts, SMS, precise location, account information and external files, and record the screen; operators leveraged the OneSignal platform to push phishing links and install persistent malware on targeted South Asian government, military and diplomatic organizations. The report notes minor variant UI differences, documents an evolution in tactics (OneSignal abuse), and includes IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.