In a significant escalation, cybersecurity researchers report that the Indian‑linked advanced persistent threat (APT) known as DoNot Team (also APT‑C‑35, Mint Tempest, Origami Elephant, SECTOR02, and Viceroy Tiger) has broadened its operations beyond South Asia, now targeting European diplomatic infrastructure using its proprietary malware, LoptikMod .

From Regional to Global: DoNot APT’s Shifting Focus
First uncovered in 2016, DoNot APT has earned a reputation for precision cyber espionage against government agencies, foreign ministries, defense entities, and NGOs. Its latest campaign demonstrates a deliberate strategy shift—phasing out regional constraints to pursue high-value targets across European capitals, including foreign affairs ministries.

The Weapon: LoptikMod and Covert Delivery
At the heart of this operation is LoptikMod, a remote-access trojan (RAT) that DoNot APT has been refining since at least 2018. The malware boasts sophisticated features like anti‑VM evasion, ASCII obfuscation, and enforced single-instance execution—techniques tailored to bypass sandbox detection and prevent automated analysis.

Delivery typically begins with highly crafted phishing emails. These messages impersonate defense figures—like an Italian Defense Attaché—to lend credibility. Recipients receive an email containing a Google Drive link to a RAR archive containing a malicious executable disguised as a PDF.

Once launched, the RAT installs itself via scheduled tasks to ensure persistence. The malware then initiates a hidden connection to command‑and‑control (C2) infrastructure to exfiltrate data, download secondary modules, and execute directives—all under the radar.

Vectoring Subtlety: Spear‑Phishing and Deception
Trellix’s analysis highlighted the attackers’ attention to detail. For example, they used HTML‑encoded UTF‑8 formatting in email text to correctly render special characters—such as the accented ‘é’ in “Attaché”—thereby enhancing the illusion of legitimacy.

The use of genuine free services (like Gmail and Google Drive) further helps the campaign slip past automated email filters and bypass awareness from security teams.

Espionage Motives and Sectoral Impact
Trellix’s report attributes the assault to pure cyber spying—targeting diplomatic communications and foreign affairs networks. Although the precise nature of stolen data remains unclear (C2 infrastructure was found inactive during analysis), the campaign aligns with typical DoNot APT tactics: patient surveillance, systematic data theft, and embedded, long‑term control.

By maintaining access over extended durations, the attackers can quietly exfiltrate sensitive files, monitor email correspondence, harvest credentials, and possibly move laterally within diplomatic institutions.

C2 Infrastructure: Silent, But Not Dormant
Interestingly, researchers found the C2 server associated with this campaign dormant at the time of investigation. The server may have been taken offline or relocated—a tactic often used to evade law enforcement scrutiny and prolong the operation.

Although this makes it difficult to fully assess the malware’s scope and objectives, its mere presence confirms ongoing espionage activity that has surpassed regional limitation.

Mitigation and Defense Strategies
Given the sophistication and expansion of DoNot APT’s campaign, cybersecurity teams across government sectors are urged to escalate defenses:

  • Email Security: Enforce strict policies against unsolicited archive attachments and drive‑based downloads. Implement URL inspection and domain reputation filtering.
  • Endpoint Monitoring: Deploy behavioral detection that flags abnormal scheduled tasks or binary execution from temporary directories.
  • Malware Analysis Environments: Utilize sandbox systems that counter anti‑VM tactics. Apply memory analysis tools to detect obfuscated payloads.
  • Credential Hardening: Enforce MFA for all diplomatic and defense personnel. Monitor for unusual access patterns or spikes in data exfiltration.

Looking Ahead
This escalation in DoNot APT’s tactics marks a troubling evolution—from targeting South Asian institutions to explicitly pursuing European diplomatic operations. The campaign’s careful blending of social engineering, targeted malware, and stealth infrastructure underscores a broader trend: nation‑linked APT groups adapting to strategically important geographies.

Western governments and their allies are now waking up to this new threat vector. As cyber espionage intensifies, the international cybersecurity community must re‑examine trust assumptions—especially surrounding cloud‑based tools, OS scheduling, and email formatting—or risk surrendering diplomatic ground to covert adversaries.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *