VICEROY TIGER

Aliases: OPERATION HANGOVER, Donot Team, APT-C-35, SectorE02, Orange Kala

First seen
2015-01-01 00:00:00
Origin
IN
Primary motivation
espionage
Sophistication
intermediate
Resource level
organization
Actor type
nation-state
Last IoC activity
2026-06-16 12:35:09
Profile updated
2026-07-07 11:47:59

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Targeted regions: country_code:pk country_code:in

Context

VICEROY TIGER is an adversary with a nexus to India that has historically targeted entities throughout multiple sectors. Older activity targeted multiple sectors and countries; however, since 2015 this adversary appears to focus on entities in Pakistan with a particular focus on government and security organizations. This adversary consistently leverages spear phishing emails containing malicious Microsoft Office documents, malware designed to target the Android mobile platform, and phishing activity designed to harvest user credentials. In March 2017, the 360 Chasing Team found a sample of targeted attacks that confirmed the previously unknown sample of APT's attack actions, which the organization can now trace back at least in April 2016. The chasing team named the attack organization APT-C-35. In June 2017, the 360 Threat Intelligence Center discovered the organization’s new attack activity, confirmed and exposed the gang’s targeted attacks against Pakistan, and analyzed in detail. The unique EHDevel malicious code framework used by the organization.

Reports & references

  • pwc.com — Yir Cyber Threats Report Download (report)
  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • github.com — Unveiling An Indian Cyberattack Infrastructure Appendixes (report)
  • ti.360.net — Latest Activity Of Apt C 35 (report)
  • netscout.com — Donot Team Leverages New Modular Malware Framework South Asia (report)
  • ti.360.net — Donot Group Is Targeting Pakistani Businessman Working In China En (report)
  • CrowdStrike — Index (report)
  • Palo Alto Unit 42 — Updated Backconfig Malware Targeting Government And Military Organizations (report)
  • Palo Alto Unit 42 — Threat Assessment Hangover Threat Group (report)
  • blog.cyble.com — Donot Apt Group Delivers A Spyware Variant Of Chat App (report)
  • CrowdStrike — Viceroy Tiger (report)

External references