logo

DONOT's Attack On Maritime & Defense Manufacturing

ID: b47c9f72-8541-595e-a6a8-16e6a9f3ac0b

STIX ID: report--b47c9f72-8541-595e-a6a8-16e6a9f3ac0b

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

This report describes a DONOT (APT‑C‑35) campaign that uses malicious .LNK files containing PowerShell to extract an encrypted lure RTF and stager DLL, establishes persistence via scheduled tasks invoking rundll32.exe, communicates with AES-encrypted C2 servers (with dynamically generated backup domains), and collects system information to guide payload delivery; the writeup includes technical indicators (hashes, domain, IP), TTP mapping to MITRE ATT&CK, and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.