Skip to content

DoNot APT Group Launches Sophisticated Cyber Espionage Campaign Against Italian Ministry of Foreign Affairs and Other European Nations

A convincing spear-phishing email tricks European diplomats. The DoNot APT group's latest campaign expands its reach, raising concerns about data security.

there was a room in which people are sitting in the chairs,in front of a table looking into the...
there was a room in which people are sitting in the chairs,in front of a table looking into the laptop and doing something,beside them there are many flee xi in which different advertisements are present which different text.

DoNot APT Group Launches Sophisticated Cyber Espionage Campaign Against Italian Ministry of Foreign Affairs and Other European Nations

A sophisticated cyber espionage campaign has been uncovered, targeting the Italian Ministry of Foreign Affairs and other European nations. The attack, attributed to the Donut APT group, began with a convincing spear-phishing email impersonating official diplomatic correspondence.

The phishing email contained a malicious Google Drive link, leading recipients to a RAR archive named SyClrLtr.rar. Upon execution, the archive deployed notflog.exe, which then triggered a batch file in the system's temporary directory. The malware established a scheduled task, 'PerformTaskMaintain', to ensure persistence and communicate with the attackers' command-and-control server every 10 minutes. The payload was associated with LoptikMod malware, a tool exclusively used by the Donut APT group since 2018. This recent campaign marks an expansion of the group's targets, following their initial focus on the Italian Ministry of Foreign Affairs. The ultimate goal of the attack was to establish a foothold within the target's infrastructure and exfiltrate sensitive information.

The Donut APT group's recent activities underscore their persistent interest in gathering sensitive information from European foreign affairs ministries. As the campaign expands to include Italy and other unspecified nations, organizations are urged to remain vigilant against such targeted attacks and to implement robust cybersecurity measures.

Read also:

Latest