Esperts found new DoNot Team APT group’s Android malware
ID: c4251083-6c82-5801-bb2e-d420c7355390
STIX ID: report--c4251083-6c82-5801-bb2e-d420c7355390
Feed Name: Security Affairs
CYFIRMA researchers linked a new Android malware family named "Tanzeem" to the Indian APT group DoNot Team (APT‑C‑35/Origami Elephant). The malicious app masquerades as a chat client, requests Accessibility permissions, can exfiltrate call logs, contacts, SMS, precise location, account information and external files, and record the screen; operators leveraged the OneSignal platform to push phishing links and install persistent malware on targeted South Asian government, military and diplomatic organizations. The report notes minor variant UI differences, documents an evolution in tactics (OneSignal abuse), and includes IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
