Researchers linked the threat actor DoNot Team to a new Android malware that was employed in highly targeted cyber attacks.
The DoNot APT group, also known as APT-C-35 and Origami Elephant, has been active since 2016 and focuses on government and military organizations in South Asian countries.
The recently discovered Android malware, named 'Tanzeem' and 'Tanzeem Update', mimics chat functionality and uses the OneSignal platform for delivering phishing links through notifications.
The malware gathers call logs, contacts, SMS messages, locations, account information, and files stored in external storage, and can also record the screen.