Home/Threat Actor/DoNot Team
Threat Actor

DoNot Team

donot_team_apt_c_35 · india · active since 2016

DoNot Team (APT-C-35 / SectorE02 / Origami Elephant / Viceroy Tiger / G0157) is a suspected India-aligned cyber-espionage cluster active since at least 2016 with its highest-confidence public attribution event the Amnesty International Security Lab October 2023 report tying DoNot Team operations to Indian commercial cyber-mercenary INNEFU Labs, one of the most operationally-specific public attribution findings for any India-aligned cluster, moving attribution beyond country-level framing toward specific commercial-contractor identification, responsible for sustained operations against Pakistani, Bangladeshi, Sri Lankan, Nepali, broader South-Asian regional targets, the distinctive Indian-domestic-dissident victim category (Kashmiri activists, Sikh political figures, Muslim-minority activists) and the Sikh-diaspora-activist victim category in Canada, UK, US, Australia, and Germany (a targeting pattern that became politically consequential in international context following the June 2023 killing of Hardeep Singh Nijjar in Canada and the subsequent Canadian government allegation of Indian government involvement), defined operationally by the signature Yty modular Windows malware framework (Cisco Talos April 2018 disclosure), Gedit downloader, StealJob, DarkMusical, Firestarter Android, DoNot Lite toolkit, and by Android mobile implants delivered via trojanized clones of legitimate Indian government apps including the Kavach two-factor authentication app used by Indian government personnel.

operationally distinct from peer India-aligned clusters SideWinder, Patchwork, and Bitter (all already covered) on toolkit, victim emphasis (domestic- and-diaspora dissident surveillance vs external-target collection), and tradecraft.

india confidence: high 21 aliases

Profile

DoNot Team (also tracked as APT-C-35, SectorE02, Origami Elephant, Viceroy Tiger, and MITRE ATT&CK G0157) is a suspected India- aligned cyber-espionage cluster active since at least 2016 with its highest-confidence public attribution event the Amnesty International Security Lab October 2023 report tying DoNot Team operations to Indian commercial cyber-mercenary / private- contractor INNEFU Labs (an Indian cybersecurity company that has bid for and won contracts with Indian government entities). The Amnesty investigation represented one of the most operationally-specific public attribution findings for any India-aligned cluster, moving attribution beyond country-level "India-aligned suspected" framing toward specific commercial- contractor identification. Whether INNEFU operates DoNot directly, contracts operations to other entities, or operates on behalf of specific Indian government entities (R&AW / IB / NTRO) has not been formally established. No formal US, UK, EU, or other government attribution event has been issued. The cluster is operationally distinct from peer India-aligned clusters in this corpus on several meaningful dimensions: First, DoNot's signature operational pattern is sustained targeting of Indian-domestic dissidents, Kashmiri activists, Sikh political figures, Muslim-minority activists, alongside sustained targeting of Sikh-diaspora activists in Canada, the United Kingdom, the United States, Australia, and Germany. This domestic-and-diaspora dissident-surveillance pattern distinguishes DoNot from SideWinder (Pakistan-government-and-military external focus), Patchwork (Pakistani-government external focus), and Bitter (Pakistan/China/Bangladesh external focus), all of which operate against external rather than India-domestic-or-diaspora targets. The domestic-surveillance pattern became politically consequential in international context following the June 2023 killing of Sikh activist Hardeep Singh Nijjar in Canada and the September 2023 Canadian government public allegation of Indian government involvement.

while formal attribution of any specific Sikh-diaspora cyber operation to DoNot Team specifically (rather than to Indian state activity broadly) has not been established, the cluster's documented Sikh-diaspora targeting pattern constitutes a relevant operational data point for that broader policy context. Second, DoNot's toolkit centers on the Yty modular Windows malware framework (Cisco Talos April 2018 detailed analysis), Gedit downloader, StealJob, DarkMusical, Firestarter (Android), and DoNot Lite, a distinct toolkit from BitterRAT/ARTRA (Bitter), from the SideWinder StealerBot/Backdoor.Pierogi family (SideWinder), and from Patchwork's BADNEWS lineage. Cluster- level toolkit attribution-distinguishing remains the reliable indicator rather than the shared India-alignment framing. Third, Pakistani targeting is one of multiple victim categories rather than the dominant one, distinguishing DoNot's victimology from SideWinder (where Pakistani targeting is the central mission) and Bitter (where Pakistani targeting is primary). DoNot operates across Pakistani, Bangladeshi, Sri Lankan, Nepali, Bhutanese, Burmese, Tajikistan, Kyrgyz, Indian-domestic, Sikh-diaspora, and selected European targets, a broader victim portfolio than peer India-aligned clusters. Operationally DoNot relies predominantly on spear-phishing with weaponized Office documents (CVE-2017-0199, CVE-2017-11882, CVE-2018-0802, CVE-2018-0798, CVE-2022-30190 Follina) followed by Yty implant deployment, with Android mobile implants delivered via fake third-party app stores, trojanized clones of legitimate Indian government apps (notably Kavach two-factor authentication used by Indian government personnel), and targeted APK file delivery via spear-phishing. The cluster has not demonstrated 0day-development capability and primarily relies on rapid weaponization of disclosed n-day vulnerabilities alongside social-engineering tradecraft. A handful of operational notes: First, the post-Amnesty-October-2023 INNEFU Labs attribution has not produced observable operational pause. The cluster continues to operate through 2024 and into 2025 per ESET, Amnesty International, Recorded Future, and other vendor tracking. Second, the contractor-versus-direct framing for India-aligned cluster operations is now better-established for DoNot Team than for SideWinder / Patchwork / Bitter, making DoNot the cluster with the most-specific contractor-level attribution among the publicly-tracked India-aligned cluster ecosystem. The pattern resembles the broader cluster-contractor patterns observable in some China-aligned ecosystems (APT41, Earth Lusca, RedHotel) and in the Iranian cluster ecosystem (Najee Technology Hooshmand and Secnerd LLC sanctioned in August 2024 for Pioneer Kitten operations). Third, the India-aligned cluster ecosystem now has four publicly- tracked distinct clusters in this corpus: SideWinder, Patchwork, Bitter / APT-C-08, and DoNot Team / APT-C-35. Whether the four clusters share infrastructure, tooling, or personnel via common contractors or service entities has been analytically open across vendor reporting. The INNEFU-DoNot connection from Amnesty 2023 is one specific data point in the broader open question.

Aliases

21
donotdonot teamdonot_teamdonotteamapt-c-35apt_c_35aptc35sectore02sector e02sector_e02origami elephantorigami_elephantorigamielephantviceroy tigerviceroy_tigerviceroytigerinnefu adjacencyinnefu_labs_adjacencyg0157atk 230atk230

Notable Campaigns

9
2024-2025Continued Operations (2024-2025)
2023Amnesty International Security Lab: INNEFU Labs Attribution (October 2023)
2020-2024Sikh Diaspora Global Targeting (2020-2024)
2019-2024Kashmir and Indian Domestic Dissident Targeting (2019-2024)
2019-2024Android Mobile Implant Distribution (2019-2024)
2018-2024ESET: DoNot Continued Tracking (2018-2024)
2018Trend Micro: DoNot Team Targets South Asia (March 2018)
2018Cisco Talos: Yty Framework Analysis (April 2018)
2016-2017Pre-Disclosure Pakistan-Focused Operations (2016-2017)

Attribution & Reporting

Attributed by
Amnesty International Security LabTrend MicroCisco TalosESETRecorded Future Insikt GroupMandiant / FireEyeMicrosoftKaspersky GReATQiAnXin Threat Intelligence Center360 Threat Intelligence CenterSentinelOneCluster25CyfirmaSECUINFRA Falcon TeamGroup-IBCitizen Lab (University of Toronto)Access NowFront Line Defenders
Key reporting
reportTrend Micro: DoNot Team Targets South Asia (March 2018), seminal cluster naming
reportCisco Talos: DoNot Android Yty Framework Analysis (April 2018), signature Yty framework disclosure
reportESET: Operation DoNot Targets Government in South Asia (March 2018)
reportESET: DoNot Team Leverages New Modular Malware Framework Against South Asia (October 2021)
reportESET: DoNotGo Spyware Attempts to Target Pakistani Officials (2023)
reportAmnesty International Security Lab: DoNot Cyber-Mercenary, India Spyware (October 2023), seminal commercial-contractor attribution to INNEFU Labs
reportRecorded Future Insikt Group: TAG-44 / DoNot Continued Tracking (multiple years)
reportQiAnXin Threat Intelligence Center: APT-C-35 DoNot Tracking (Chinese-language, multiple years)
report360 Threat Intelligence Center: APT-C-35 Tracking
reportSekoia: DoNot Team India Tracking (2023-2024)
reportCyfirma: DoNot APT Tracking (2024)
reportCluster25: DoNot Operational Profile (2023-2024)
reportMalpedia Actor Profile: DoNot Team
reportMITRE ATT&CK Group G0157, DoNot Team

Operational

State sponsor

Suspected India-aligned cyber-espionage cluster. Attribution to India is grounded in victimology (concentrated targeting of Pakistani, Bangladeshi, Sri Lankan, Nepali, Kashmiri, and Indian-Sikh-diaspora entities of regional adversarial or domestic- surveillance interest to India), language artifacts, operational hours consistent with Indian Standard Time, and infrastructure- attribution indicators. The most operationally consequential attribution event is Amnesty International Security Lab's October 2023 report which tied DoNot Team operations to Indian commercial cyber-mercenary / private-contractor INNEFU Labs (an Indian cybersecurity company that has bid for and won contracts with Indian government entities). The INNEFU Labs connection represented one of the most operationally-specific public attribution findings for any India-aligned cluster, moving attribution beyond country-level "India-aligned suspected" framing toward specific commercial-contractor identification. Whether INNEFU Labs operates DoNot Team directly, contracts operations to other commercial entities, or operates on behalf of specific Indian government entities (Research and Analysis Wing / R&AW, Intelligence Bureau / IB, National Technical Research Organisation / NTRO) has not been formally established. No formal US, UK, EU, or other government attribution event has been issued.

the India-aligned framing rests on vendor research consensus and the Amnesty Security Lab investigation rather than on formal state attribution. The cluster is operationally distinct from SideWinder (already covered as sidewinder.yaml), Patchwork (already covered as patchwork.yaml), and Bitter (already covered as bitter_apt_c_08.yaml), all India-aligned, with distinct toolkit, distinct victim emphasis (notably the domestic-dissident-and-Sikh-diaspora targeting that distinguishes DoNot), and distinct operational tradecraft.

Motivations
espionage, intelligence_gathering, dissident_surveillance, journalist_surveillance, human_rights_activist_surveillance, religious_minority_surveillance, domestic_political_surveillance, diaspora_surveillance, regional_adversary_collection, cross_border_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)26/60 · 43%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTASIGNED ANDROID APK FAKE PLAY STORESTEAL JOBSTEALJOB
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin