The DoNot APT group, possibly based in India, has expanded its espionage operations by targeting European foreign ministries with a new malware called LoptikMod. Their sophisticated campaigns involve spear-phishing, malware obfuscation, and stealthy command-and-control communications to steal sensitive information. #DoNotAPT #LoptikMod
Keypoints
- The DoNot APT group has been active since 2016, primarily targeting government and defense entities in South Asia and Europe.
- Their recent campaign used spear-phishing emails impersonating defense officials to deliver the LoptikMod malware.
- Malware was concealed in password-protected RAR files with disguised executables to deceive users.
- Stealth tactics include binary obfuscation, anti-VM checks, and runtime API loading to evade detection.
- The malware communicates with a C2 server over HTTPS, collecting system data and potentially downloading additional payloads.