Alpha Cyber

Unmasking Mobile Espionage: Forensic Analysis on Donot Indian APT’s Android Malware Operations

Advanced Persistent Threats (APTs) are expanding their offensive footprint into mobile ecosystems and organizations in South Asia remain prime targets.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Donot APT Hackers

The Infrastructure Map of DONOT APT’s Android Spyware

Advanced Persistent Threats (APTs) are expanding their offensive footprint into mobile ecosystems and organizations in South Asia remain prime targets. Our Threat Intelligence & Mobile Forensics Team recently uncovered a malicious Wechat APK Trojan linked to Donot (APT‑C‑35), an Indian group long associated with targeted espionage in India and surrounding regions.

As part of our Mobile Malware Forensic Analysis Service, we map the attacker’s infrastructure, trace operational behavior, and provide actionable intelligence that organizations can immediately block.

During our investigation, we performed full-scale static and behavioral analysis using advanced mobile security frameworks. Using MOBSF, the malicious APK surfaced as heavily obfuscated, permission‑abusing, and designed to harvest sensitive personal and device data aligning with known Donot APT tactics.

Quick Snapshot: Wechat APK Trojan

MOBSF Donot APT APK Malware Info

AttributeValue
Malware NameWechat APK Trojan
MD5242e05f06544349256470110fdb433b5
SHA10efd8ab6d9ad4d2dc5ad072bdbbd6a9cf15b9a41
SHA25670df22a25cbb8715f1d3dd693123ac92203b3a27dfc6c7fa0e48239cf15cbf02
MOBSF Security Score46/100
File Size1.27MB

Key Forensic Findings

1. Anti‑VM Evasion

The trojan checks Build.MANUFACTURER to detect analysis in virtual environments, indicating deliberate evasion of automated malware sandboxes.

MOBSF Donot APT APK Malware Dangerous Anti-VM Code

2. Extensive Surveillance Capabilities

The malware systematically collects personal and device data, including:

  • SMS messages
  • Call logs
  • File paths & filenames
  • Location data
  • Account information
  • Wi‑Fi & network metadata

MOBSF Donot APT APK Malware Dangerous Permissions

3. File & Data Exfiltration Pipeline (Behavioral Analysis)

Below is a structured view of observed malicious behaviors (extracted during dynamic analysis):

MOBSF Donot APT Malware Android API

Rule IDBehaviourCategoryFile Reference
00004Get filename & store in JSONFile collectionjii/optr/service/aleole/nqwer.java
00005Get absolute path & store in JSONFiled/a/a/c/a.java; jii/optr/service/aleole/nqwer.java
00009Insert cursor data into JSONFile,
00010Read SMS & Call Log → JSONSMS/Call log collectiond/a/a/g/d.java
00013Read file into a streamFile,
00014Read file → stream → JSONFilejii/optr/service/aleole/nqwer.java
00016Capture device location & storeLocationd/a/a/g/e.java
00022Open file by absolute pathFiled/a/a/c/a.java; jii/optr/service/aleole/nqwer.java
00024Write Base64‑decoded fileReflection/Filea/a/a/a/a.java; jii/optr/service/aleole/nqwer.java
00030Connect to remote server via URLNetworkd/a/a/f/b.java

4. Abused Android Permissions (18 of 25 High‑Risk)

The trojan requests a broad set of sensitive permissions, far beyond the scope of a normal messaging app:

READ_SMS, SEND_SMS, READ_CALL_LOG, RECORD_AUDIO, ACCESS_FINE_LOCATION, GET_ACCOUNTS, READ_CONTACTS, WRITE_SETTINGS, READ/WRITE_EXTERNAL_STORAGE, INTERNET, RECEIVE_BOOT_COMPLETED, and more.

This permission combination enables surveillance, persistence, and exfiltration a hallmark of APT‑grade mobile malware.

MOBSF Donot APT APK Malware Abused Permissions

Infrastructure Awareness: IOC Table for Defensive Blocking

Organizations should proactively block and alert on the following Indicators of Compromise associated with this APK and similar Donot APT mobile tooling.

Note: No live malicious domains or IPs are provided. This table is safe and awareness‑oriented.

IOC TypeValueDescription
File Hash (MD5)242e05f06544349256470110fdb433b5Malicious APK identifier
File Hash (SHA1)0efd8ab6d9ad4d2dc5ad072bdbbd6a9cf15b9a41Cross‑tool integrity reference
File Hash (SHA256)70df22a25cbb8715f1d3dd693123ac92203b3a27dfc6c7fa0e48239cf15cbf02Strong cryptographic IOC
Package NameSuspicious WeChat‑themed packageUsed for masquerading
Behavior PatternSMS/Call log harvestingSurveillance indicator
Behavior PatternDevice location exfiltrationTracking indicator
Behavior PatternBase64‑decoded file writesPossible payload staging
Behavior PatternRemote server connection attemptsC2 communication attempts

Why This Matters to Your Organization

Mobile devices are now primary endpoints for executives, diplomats, journalists, and government employees. APT groups especially Donot continue to weaponize fake productivity or communication apps to infiltrate high‑value targets.

Our Android Malware Forensics & Threat Infrastructure Mapping Service provides:

  • Deep mobile malware reverse engineering
  • Attacker infrastructure mapping
  • IOC enrichment & detection engineering
  • Threat attribution intelligence
  • Executive‑level risk reports
  • Defensive hardening recommendations

Protect Your Mobile Fleet Before APTs Target It

If your organization relies heavily on Android devices, now is the time to strengthen mobile threat detection.
Our specialists can perform rapid triage, full forensic investigations, or continuous threat monitoring tailored to your environment.

Ready to safeguard your mobile ecosystem?

Contact Us Team for a full forensic assessment today.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]