Threat intelligence
- Suspected origin
- India
- First seen
- 2016-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Embassies, Defense, Government
- TLP
- WHITE
(ASERT) In late January 2018, ASERT discovered a new modular malware framework we call “yty”. The framework shares a striking resemblance to the EHDevel framework. We believe with medium confidence that a team we call internally as “Donot Team” is responsible for the new malware and will resume targeting of South Asia.
In a likely effort to disguise the malware and its operations, the authors coded several references into the malware for football—it is unclear whether they mean American football or soccer. The theme may allow the network traffic to fly under the radar.
The actors use false personas to register their domains instead of opting for privacy protection services. Depending on the registrar service chosen, this could be seen as another cost control measure. The actors often used typo-squatting to slightly alter a legitimate domain name. In contrast, the registration information used accurate spelling, possibly indicating the domain naming was intentional, typos included. Each unique registrant usually registered only a few domains, but mistakenly reused phone numbers or the registration data portrayed a similar pattern across domains.
Also known as
APT-C-35Mint TempestOrigami ElephantSectorE02
Coverage 1
threat-intel
A previously undocumented Go-based malware, GoSerpent, has been actively targeting government and diplomatic entities in Southeast Asia since 2021, with a renewed surge in activity in 2026. Developed by the threat actor…
