• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CVE-2024-37079

    CISA Flags Actively Exploited VMware vCenter RCE Flaw in KEV Catalog

    Data Privacy Week 2026

    Canada Marks Data Privacy Week 2026 as Commissioner Pushes for Privacy by Design

    Nike cyberattack

    Nike Probes Possible Cybersecurity Incident Following Dark Web Claims

    European Commission investigation into Grok AI

    European Commission Launches Fresh DSA Investigation Into X Over Grok AI Risks

    Data Privacy Week 2026

    Data Privacy Week 2026: Why Secure Access is the New Data Protection Perimeter

    Microsoft Emergency Fix Released for Exploited Office Zero-Day

    Microsoft Releases Emergency Fix for Exploited Office Zero-Day

    ShinyHunters, CL0P Return with New Claimed Victims

    ShinyHunters, CL0P Return with New Claimed Victims

    CISA Adds Five Enterprise Software Flaws to Known Exploited Vulnerabilities Catalog

    CISA Adds Five Enterprise Software Flaws to Known Exploited Vulnerabilities Catalog

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Data Privacy Week 2026

    Canada Marks Data Privacy Week 2026 as Commissioner Pushes for Privacy by Design

    European Commission investigation into Grok AI

    European Commission Launches Fresh DSA Investigation Into X Over Grok AI Risks

    Phishing Toolkits, Vishing, Okta, Okta Threat Intelligence

    Phishing Kits Now Sync With Live Phone Scammers to Defeat Multifactor Authentication

    social media ban for children

    UK Turns to Australia Model as British Government Considers Social Media Ban for Children

    Grok AI Image Abuse

    Grok Image Abuse Prompts X to Roll Out New Safety Limits

    RedVDS, RedVDS Tool, RedVDS Infrastructure, Microsoft, Fraud, Scam

    Microsoft Crushes Cybercrime Subscription Service Behind $40 Million Fraud Spree

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Government Cyber Action Plan

    UK Moves to Close Public Sector Cyber Gaps With Government Cyber Action Plan

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CVE-2024-37079

    CISA Flags Actively Exploited VMware vCenter RCE Flaw in KEV Catalog

    Data Privacy Week 2026

    Canada Marks Data Privacy Week 2026 as Commissioner Pushes for Privacy by Design

    Nike cyberattack

    Nike Probes Possible Cybersecurity Incident Following Dark Web Claims

    European Commission investigation into Grok AI

    European Commission Launches Fresh DSA Investigation Into X Over Grok AI Risks

    Data Privacy Week 2026

    Data Privacy Week 2026: Why Secure Access is the New Data Protection Perimeter

    Microsoft Emergency Fix Released for Exploited Office Zero-Day

    Microsoft Releases Emergency Fix for Exploited Office Zero-Day

    ShinyHunters, CL0P Return with New Claimed Victims

    ShinyHunters, CL0P Return with New Claimed Victims

    CISA Adds Five Enterprise Software Flaws to Known Exploited Vulnerabilities Catalog

    CISA Adds Five Enterprise Software Flaws to Known Exploited Vulnerabilities Catalog

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Data Privacy Week 2026

    Canada Marks Data Privacy Week 2026 as Commissioner Pushes for Privacy by Design

    European Commission investigation into Grok AI

    European Commission Launches Fresh DSA Investigation Into X Over Grok AI Risks

    Phishing Toolkits, Vishing, Okta, Okta Threat Intelligence

    Phishing Kits Now Sync With Live Phone Scammers to Defeat Multifactor Authentication

    social media ban for children

    UK Turns to Australia Model as British Government Considers Social Media Ban for Children

    Grok AI Image Abuse

    Grok Image Abuse Prompts X to Roll Out New Safety Limits

    RedVDS, RedVDS Tool, RedVDS Infrastructure, Microsoft, Fraud, Scam

    Microsoft Crushes Cybercrime Subscription Service Behind $40 Million Fraud Spree

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Government Cyber Action Plan

    UK Moves to Close Public Sector Cyber Gaps With Government Cyber Action Plan

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

APT Group DONOT Launches Cyberattack on Pakistan’s Maritime and Defense Industry

As per reports by Cyble Research and Intelligence Labs (CRIL), the APT group DONOT, also known as APT-C-35, has been active since 2016 and is primarily recognized for its persistent cyber espionage activities.

Ashish Khaitan by Ashish Khaitan
November 18, 2024
in Firewall Daily, Cyber News, Dark Web News
0
APT group DONOT
791
SHARES
4.4k
VIEWS
Share on LinkedInShare on Twitter

A new hacker collective, known as the APT group DONOT, has targeted critical sectors of Pakistan’s economy, specifically the maritime and defense manufacturing industries.  By leveraging advanced malware and targeted social engineering strategies, the DONOT hacker group has successfully compromised sensitive infrastructure.   

As per reports by Cyble Research and Intelligence Labs (CRIL), the APT group DONOT, also known as APT-C-35, has been active since 2016 and is primarily recognized for its persistent cyber espionage activities. Historically, this hacker group has focused on government agencies, military entities, and diplomatic missions, with particular emphasis on countries in South Asia.

Its operations are characterized by a high degree of stealth, using sophisticated malware and custom-built tools to infiltrate target networks.  

The Rise of APT Group DONOT

APT Group DONOT
Cyble Vision Threat Library (Source: Cyble)

The DONOT hacker group has previously attacked organizations by exploiting vulnerabilities in government and military systems, often using phishing emails and malicious attachments as initial infection vectors. This time, however, their focus has shifted to Pakistan’s critical manufacturing sectors, which support the country’s maritime and defense industries. Given the sensitive nature of these sectors, the attack has profound implications for both economic stability and national security.  

The recent cyberattack, which Cyble researchers first identified in a report, centers on a campaign targeting the manufacturing facilities that supply equipment for Pakistan’s defense and maritime sectors. This targeted approach suggests that the DONOT hacker group is not just interested in gaining general access to systems, but rather in obtaining specific industrial and military intelligence.  

The initial infection vector in this campaign was a malicious LNK (shortcut) file, which was sent in a spam email disguised as a legitimate Rich Text Format (RTF) document. This LNK file was designed to appear as though it contained encrypted data, enticing the victim to open it. Once clicked, the file triggered several PowerShell commands that downloaded additional malware, including a DLL file that acted as a “stager” for further exploits.  

report-ad-banner

Upon execution, the malicious LNK file activated a series of commands that used PowerShell scripts to download and decrypt further payloads. These payloads were then deployed onto the compromised system, establishing a foothold that allowed the malware to persist on the infected machine. To maintain access to the network, the malware scheduled a task to execute the payload every five minutes.  

Advanced Malware and Persistence Mechanisms  

The malware employed by the DONOT hacker group in this attack is highly advanced, utilizing multiple encryption techniques to avoid detection by traditional security systems. The group introduced a new method of Command and Control (C&C) server communication. The malware uses AES encryption and Base64 encoding to obfuscate its communications, making it more difficult for security software to identify malicious activity.  

Once the malware established its presence, it initiated a POST request to the primary C&C server, transmitting a unique device ID to authenticate the compromised machine. If the C&C server responded positively, the malware would download further payloads, configure the system for persistence, and prepare for additional stages of the attack.  

In addition to encrypting communication between the victim machine and the C&C server, the hacker group DONOT also employed random domain generation for backup C&C servers. This strategy ensures that, even if the primary server is taken down, the malware can continue to operate through secondary, dynamically generated domains.  

Technical Analysis: How the Attack Unfolded  

APT Group DONOT
Infection Chain of APT Group DONOT (Source: Cyble)

The malicious process begins with the execution of a PowerShell script hidden inside the LNK file. This script decrypts both the lure RTF file and the DLL payload using a simple XOR operation. The files are then extracted to the victim’s temporary directory. Following extraction, the malware deletes the PowerShell script and opens the lure document to further entice the victim.  

The lure document itself was linked to Karachi Shipyard & Engineering Works (KS&EW), a prominent Pakistani defense contractor. This suggests that the attacker’s primary objective was to infiltrate the defense sector by exploiting industry-specific targets.  

Once the DLL is executed, it initiates a process that extracts critical configuration data, including server addresses, encryption keys, and other task parameters, from an embedded JSON file. The malware then uses this information to communicate securely with the C&C server, requesting further instructions on how to proceed with the attack.  

The stager malware also checks for the existence of a scheduled task named “Schedule.” If this task is absent, the malware creates it, ensuring that the malicious DLL is executed every five minutes, thereby maintaining persistence on the compromised system. This tactic is part of a broader strategy to ensure the malware continues to run undetected for as long as possible.  

Random Domain Generation for Backup C&C Servers  

A particularly notable feature of this attack is the use of random domain generation. The DONOT hacker group has taken extra precautions to avoid detection by generating backup domains for its C&C servers. These domains are created by concatenating words from a hardcoded array of values, followed by the selection of a random top-level domain (TLD). This dynamic method of domain generation makes it harder for cybersecurity teams to shut down the C&C infrastructure, even if some of the domains are blacklisted.  

The configuration file also includes fallback server URLs that are periodically updated in response to changes in the primary C&C server’s status. This flexibility ensures that the hacker group can maintain control over compromised systems, regardless of disruptions to their communication infrastructure.  

New Encryption Methods and Payload Delivery 

In this campaign, the DONOT hacker group introduced a more sophisticated approach to payload delivery. Unlike previous campaigns where the decryption key was hardcoded into the configuration file, this time, the decryption key was embedded within the binary itself, making it harder for analysts to detect.  

The malware’s ability to download, decrypt, and execute additional payloads represents a more advanced and nuanced approach to cyber espionage. Once the payload is successfully decrypted, the malware creates a scheduled task to execute the final payload, which could range from data exfiltration tools to additional malicious code capable of causing long-term damage to the compromised systems.  

The recent cyberattack by the DONOT APT group marks a significant escalation in their tactics, using advanced methods like PowerShell exploitation, dynamic domain generation, and enhanced encryption to evade detection. This attack, targeting Pakistan’s sensitive maritime and defense sectors, highlights the growing threat posed by such sophisticated groups.   

To counter this, organizations must strengthen cybersecurity defenses by deploying robust endpoint detection, conducting regular audits, and training employees to recognize phishing attempts. Proactive threat hunting and a clear incident response plan are essential to defending against future attacks. Vigilance and preparedness remain critical in mitigating the risks from advanced persistent threats like DONOT. 

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: APT group DONOTAPT-C-35DONOT hacker groupPowerShellThe Cyber ExpressThe Cyber Express News
Previous Post

European Club and Media Giant Abandon X Amid Growing Hate Speech Concerns

Next Post

Black Friday or Black Fraud-day? A Prime Time for Fraud and Cyberattacks

Next Post
Black Friday

Black Friday or Black Fraud-day? A Prime Time for Fraud and Cyberattacks

Threat Landscape Reports 2025

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

CVE-2024-37079
Firewall Daily

CISA Flags Actively Exploited VMware vCenter RCE Flaw in KEV Catalog

January 27, 2026
Data Privacy Week 2026
Cyber News

Canada Marks Data Privacy Week 2026 as Commissioner Pushes for Privacy by Design

January 27, 2026
Nike cyberattack
Firewall Daily

Nike Probes Possible Cybersecurity Incident Following Dark Web Claims

January 27, 2026
European Commission investigation into Grok AI
Regulations

European Commission Launches Fresh DSA Investigation Into X Over Grok AI Risks

January 27, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information