logo

DONOT Group Deploys Malicious Android Apps in India

ID: 45a76c07-e969-5d7f-ad1d-b8c51c597dce

STIX ID: report--45a76c07-e969-5d7f-ad1d-b8c51c597dce

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2025-01-21

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Cyfirma identified an ongoing DONOT Team (APT) campaign in which two fake Android chat apps, “Tanzeem” and “Tanzeem Update,” trick victims into enabling accessibility and other permissions, then stealthily exfiltrate call logs, contacts, messages, location and files and use push notifications to deploy additional payloads—indicating targeted intelligence gathering against individuals and organizations of interest in South Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.