logo

Indian APT Group DONOT Misuses App for Intelligence Gathering

ID: c064cd1d-9233-5d83-8f8c-9da019003022

STIX ID: report--c064cd1d-9233-5d83-8f8c-9da019003022

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2025-01-20

Date Updated: 2026-04-22

...
...

Cyfirma links Android apps named “Tanzeem”/“Tanzeem Update” to the Indian APT group DONOT; the apps abuse OneSignal for phishing, request accessibility and other sensitive permissions, harvest call logs, SMS, contacts, location and files, and exfiltrate data to Appspot-based C2 domains (e.g., toolgpt.buzz, Solarradiationneutron.appspot.com) with a reported SHA-256 hash, targeting individuals and organizations in South Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.