Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The DoNot team is linked to the new Tanzeem Android Targeting Malware operational data collection
Global Security

The DoNot team is linked to the new Tanzeem Android Targeting Malware operational data collection

AdminBy AdminJanuary 20, 2025No Comments3 Mins Read
Android Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 20, 2025Ravi LakshmananAndroid / Malware

Malicious programs for Android

The Threat actor known as Not the team has been linked to a new Android malware in a highly targeted cyberattack.

The artifacts the company in question called Tanzeem (which means “organization” in Urdu) and Tanzeem Update were spotted in October and December 2024 by cybersecurity firm Cyfirma. The apps in question were found to have the same functionality, except for minor changes in the user interface.

“Although the app is supposed to function as a chat app, it doesn’t work after installation and closes after obtaining the necessary permissions,” says Cyfirma. noted in Friday’s analysis. “The name of the program suggests that it is intended for specific individuals or groups both within and outside the country.”

DoNot Team, also tracked as APT-C-35, Origami Elephant, SECTOR02, and Viceroy Tiger, is a hacking group believed to be of Indian origin with a history of attacks using phishing emails and Android malware family to collect interesting information.

In October 2023 The threat actor was linked to a previously undocumented .NET-based backdoor named Firebird targeting few victims in Pakistan and Afghanistan.

Cyber ​​security

It is currently unclear who exactly was targeted by the latest malware, although it is suspected that it was used against specific individuals to gather intelligence against insider threats.

A notable aspect of the Android malware is its use of OneSignal, a popular customer engagement platform used by organizations to send push notifications, in-app messages, email and SMS messages. Cyfirma suggests that the library is being used to send notifications containing phishing links that lead to the deployment of malware.

Regardless of the distribution mechanism used, the program, once installed, displays a fake chat screen and prompts the victim to click the “Start Chat” button. This causes a message instructing the user to grpermissionions for Accessibility Services APIwhich allows him to perform various nefarious acts.

The app also requests access to several sensitive permissions that facilitate the collection of call logs, contacts, SMS messages, exact locations, account information, and files located on external storage. Some of the other features include screen recordings and establishing connections with a command and administrative (C2) server.

“The collected samples reveal a new tactic using push notifications that encourage users to install additional Android malware, ensuring the malware remains on the device,” Cyfirma said.

“This tactic increases the ability of malware to remain active on a target device, indicating the threat group’s intent to continue to engage in intelligence gathering for the national interest.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.