DoNot APT Hits European Ministry with New LoptikMod Malware
ID: 7133e78e-b39e-54f0-abad-00e822f5f54c
STIX ID: report--7133e78e-b39e-54f0-abad-00e822f5f54c
Feed Name: HackRead
DoNot APT (aka APT-C-35/Mint Tempest) executed a sophisticated spear‑phishing operation against a European foreign affairs ministry by impersonating defence officials and delivering a Google Drive link that downloaded SyClrLtr.rar containing notflog.exe; the payload installed a batch file, created a scheduled task for persistence (every 10 minutes), and deployed LoptikMod which collects system details, encrypts them, and communicates with a C2. The report details TTPs, IOCs (e.g., sender int.dte.afd.1@gmailcom, SyClrLtr.rar, notflog.exe), historical attribution to the group, and recommends stronger email security, network monitoring, and EDR protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
