DONOT

Malware type
spyware, rat
Family
Malware family
Last IoC activity
2026-07-10 21:01:23
Profile updated
2026-07-07 14:09:09

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:in country_code:pk

Context

Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.

Detection coverage

  • 5 YARA rules

Detection rules

  • ARKBIRD_SOLG_APT_Donot_Downloader_May_2021_1 (yara-rule)
  • ARKBIRD_SOLG_APT_MAL_Donot_Loader_June_2020_1 (yara-rule)
  • SEKOIA_Downloader_Win_Donot (yara-rule)
  • SEKOIA_Keylogger_Win_Donot (yara-rule)
  • MALPEDIA_Win_Donot_Auto (yara-rule)

Reports & references

  • research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Donot (report)
  • labs.k7computing.com — The Donot Apt (report)
  • blog.morphisec.com — Apt C 35 New Windows Framework Revealed (report)

External references