The DoNot Team hacking group has been linked to the use of a groundbreaking .NET-based backdoor, codenamed Firebird, targeting a small number of victims in Pakistan and Afghanistan.

Cybersecurity firm Kaspersky, which revealed its findings in its Q3 2023 APT trends report, said the attack chains have been configured to produce a downloader called CSVtyrei, so named because of its similarity to Vtyrei.
See also: September saw a 153% increase in ransomware attacks
The Russian company stated that “Some code in the examples appears to be malfunctioning, indicating ongoing development efforts.”.
Vtyrei (also known as BREEZESUGAR) refers to a first-stage payload and downloader strain that was previously used by the attacker to deliver a malware framework known as RTY.
DoNot Team, also known by the names APT-C-35, Origami Elephant and SECTOR02, is suspected of being of Indian origin, with its attacks using spear-phishing emails and malicious Android to spread malware.
The latest assessment by Kaspersky is based on an analysis of the suspected threat actor's dual attack sequences in April 2023, aimed at installing the Agent K11 and RTY frameworks.
The disclosure also follows the detection of new malicious activity carried out by the Pakistan-based group Transparent Tribe (also known as APT36), targeting Indian government sectors using an updated malware arsenal that includes a previously undocumented Windows trojan named ElizaRAT.
Transparent Tribe, active since 2013, has used credential harvesting and malware distribution attacks, often distributing modified installers of Indian government applications such as the multi-factor authentication and exploiting open-source command-and-control (C2) frameworks such as Mythic.
In an indication that the hacking group has turned its attention to Linux systems, Zscaler said it has identified a small set of desktop entry files that pave the way for the execution of Python-based ELF binaries, including GLOBSHELL for file exfiltration and PYSHELLFOX for stealing session data from the Mozilla Firefox.
See also: ASVEL basketball team confirms data breach due to ransomware

Codenamed “Mysterious Elephant” (also known as APT-K-47), the hacker group is credited with a spear-phishing attack that deploys a new backdoor called “ORPCBackdoor.” This backdoor is capable of executing files and commands on the victim’s computer, as well as receiving files or commands from a malicious server.
According to the Knownsec 404 team, APT-K-47 shares tools and targets with other actors, such as SideWinder, Patchwork, Confucius, and Bitter, most of whom are believed to be linked to India.
Information source: thehackernews.com
