By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: DoNot APT Expands Operations, Targets European Foreign Ministries with LoptikMod Malware
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > DoNot APT Expands Operations, Targets European Foreign Ministries with LoptikMod Malware
Computing

DoNot APT Expands Operations, Targets European Foreign Ministries with LoptikMod Malware

News Room
Last updated: 2025/07/09 at 10:53 AM
News Room Published 9 July 2025
Share
SHARE

Jul 09, 2025Ravie LakshmananMalware / Cyber Espionage

A threat actor with suspected ties to India has been observed targeting a European foreign affairs ministry with malware capable of harvesting sensitive data from compromised hosts.

The activity has been attributed by Trellix Advanced Research Center to an advanced persistent threat (APT) group called DoNot Team, which is also known as APT-C-35, Mint Tempest, Origami Elephant, SECTOR02, and Viceroy Tiger. It’s been assessed to be active since 2016.

“DoNot APT is known for using custom-built Windows malware, including backdoors like YTY and GEdit, often delivered through spear-phishing emails or malicious documents,” Trellix researchers Aniket Choukde, Aparna Aripirala, Alisha Kadam, Akhil Reddy, Pham Duy Phuc, and Alex Lanstein said.

Cybersecurity

“This threat group typically targets government entities, foreign ministries, defense organizations, and NGOs especially those in South Asia and Europe.”

The attack chain commences with phishing emails that aim to trick recipients into clicking on a Google Drive link to trigger the download of a RAR archive, which then paves the way for the deployment of a malware dubbed LoptikMod, which is exclusively put to use by the group as far back as 2018.

The messages, per Trellix, originate from a Gmail address and impersonate defense officials, with a subject line that references an Italian Defense Attaché’s visit to Dhaka, Bangladesh.

“The email used HTML formatting with UTF-8 encoding to properly display special characters like ‘é’ in ‘Attaché,’ demonstrating attention to detail to increase legitimacy,” Trellix noted in its deconstruction of the infection sequence.

The RAR archive distributed via the emails contains a malicious executable that mimics a PDF document, opening which causes the execution of the LoptikMod remote access trojan that can establish persistence on the host via scheduled tasks and connect to a remote server to send system information, receive further commands, download additional modules, and exfiltrate data.

It also employs anti-VM techniques and ASCII obfuscation to hinder execution in virtual environments and evade analysis, thereby making it a lot more challenging to determine the tool’s purpose. Furthermore, the attack makes sure that only one instance of the malware is actively running on the compromised system to avoid potential interference.

Cybersecurity

Trellix said the command-and-control (C2) server used in the campaign is currently inactive, meaning the infrastructure has been either temporarily disabled or no longer functional, or that the threat actors have moved to a completely different server.

The inactive state of the C2 server also means that it’s currently not feasible to determine the exact set of commands that are transmitted to infected endpoints and the kinds of data that are sent back as responses.

“Their operations are marked by persistent surveillance, data exfiltration, and long-term access, suggesting a strong cyber espionage motive,” the researchers said. “While historically focused on South Asia, this incident targeting South Asian embassies in Europe, indicates a clear expansion of their interests towards European diplomatic communications and intelligence.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Apple wants to update macOS in store like it does for iOS
Next Article Chipmaker Nvidia becomes most valuable company in the world at $4 trillion
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

We may finally know what happened to the water on Mars
News
Dreaming of a Dyson? Here Are 6 of Our Favorite Dyson Vacuums, Fans, and Hair Tools on Sale for Prime Day
Gadget
OpenAI set to release Chromium-based browser built around AI agent – News
News
Monkeys Will Own NFTs in a Decentralized Internet | HackerNoon
Computing

You Might also Like

Computing

Monkeys Will Own NFTs in a Decentralized Internet | HackerNoon

14 Min Read
Computing

Why Compiler Writers Care About Case-of-Case | HackerNoon

7 Min Read
Computing

The Trouble with Blaming Sci-Fi for Silicon Valley’s Obsessions | HackerNoon

13 Min Read
Computing

The Hidden Contagion Risks of Leveraged Crypto Lending | HackerNoon

11 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?