DoNot APT Expands Arsenal To Spy On VoIP Calls
ID: 7a9ce49d-1b9d-5460-ae33-6bda7cf3c21a
STIX ID: report--7a9ce49d-1b9d-5460-ae33-6bda7cf3c21a
Feed Name: Cyble Blog
Threat Score
Cyble Research and Intelligence Labs (CRIL) analyzed Android spyware attributed to the DoNot APT that weaponizes a benign Quran app and fake messaging/utility apps to steal extensive sensitive data (messages, call/VoIP recordings, screenshots, browser history, location, contacts, etc.), uses Firebase Cloud Messaging and hardcoded C2 domains (capsup.buzz, toolgpt.buzz) for control and payload delivery, and includes hashes and IOC details for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
