logo

DoNot APT Expands Arsenal To Spy On VoIP Calls

ID: 7a9ce49d-1b9d-5460-ae33-6bda7cf3c21a

STIX ID: report--7a9ce49d-1b9d-5460-ae33-6bda7cf3c21a

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2024-10-22

Date Updated: 2026-07-17

...
...

Cyble Research and Intelligence Labs (CRIL) analyzed Android spyware attributed to the DoNot APT that weaponizes a benign Quran app and fake messaging/utility apps to steal extensive sensitive data (messages, call/VoIP recordings, screenshots, browser history, location, contacts, etc.), uses Firebase Cloud Messaging and hardcoded C2 domains (capsup.buzz, toolgpt.buzz) for control and payload delivery, and includes hashes and IOC details for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.