Unmasking Mobile Espionage: Forensic Analysis on Donot Indian APT’s Android Malware Operations
Advanced Persistent Threats (APTs) are expanding their offensive footprint into mobile ecosystems and organizations in South Asia remain prime targets.

The Infrastructure Map of DONOT APT’s Android Spyware
Advanced Persistent Threats (APTs) are expanding their offensive footprint into mobile ecosystems and organizations in South Asia remain prime targets. Our Threat Intelligence & Mobile Forensics Team recently uncovered a malicious Wechat APK Trojan linked to Donot (APT‑C‑35), an Indian group long associated with targeted espionage in India and surrounding regions.
As part of our Mobile Malware Forensic Analysis Service, we map the attacker’s infrastructure, trace operational behavior, and provide actionable intelligence that organizations can immediately block.
During our investigation, we performed full-scale static and behavioral analysis using advanced mobile security frameworks. Using MOBSF, the malicious APK surfaced as heavily obfuscated, permission‑abusing, and designed to harvest sensitive personal and device data aligning with known Donot APT tactics.
Quick Snapshot: Wechat APK Trojan

| Attribute | Value |
|---|---|
| Malware Name | Wechat APK Trojan |
| MD5 | 242e05f06544349256470110fdb433b5 |
| SHA1 | 0efd8ab6d9ad4d2dc5ad072bdbbd6a9cf15b9a41 |
| SHA256 | 70df22a25cbb8715f1d3dd693123ac92203b3a27dfc6c7fa0e48239cf15cbf02 |
| MOBSF Security Score | 46/100 |
| File Size | 1.27MB |
Key Forensic Findings
1. Anti‑VM Evasion
The trojan checks Build.MANUFACTURER to detect analysis in virtual environments, indicating deliberate evasion of automated malware sandboxes.

2. Extensive Surveillance Capabilities
The malware systematically collects personal and device data, including:
- SMS messages
- Call logs
- File paths & filenames
- Location data
- Account information
- Wi‑Fi & network metadata

3. File & Data Exfiltration Pipeline (Behavioral Analysis)
Below is a structured view of observed malicious behaviors (extracted during dynamic analysis):

| Rule ID | Behaviour | Category | File Reference |
|---|---|---|---|
| 00004 | Get filename & store in JSON | File collection | jii/optr/service/aleole/nqwer.java |
| 00005 | Get absolute path & store in JSON | File | d/a/a/c/a.java; jii/optr/service/aleole/nqwer.java |
| 00009 | Insert cursor data into JSON | File | , |
| 00010 | Read SMS & Call Log → JSON | SMS/Call log collection | d/a/a/g/d.java |
| 00013 | Read file into a stream | File | , |
| 00014 | Read file → stream → JSON | File | jii/optr/service/aleole/nqwer.java |
| 00016 | Capture device location & store | Location | d/a/a/g/e.java |
| 00022 | Open file by absolute path | File | d/a/a/c/a.java; jii/optr/service/aleole/nqwer.java |
| 00024 | Write Base64‑decoded file | Reflection/File | a/a/a/a/a.java; jii/optr/service/aleole/nqwer.java |
| 00030 | Connect to remote server via URL | Network | d/a/a/f/b.java |
4. Abused Android Permissions (18 of 25 High‑Risk)
The trojan requests a broad set of sensitive permissions, far beyond the scope of a normal messaging app:
READ_SMS, SEND_SMS, READ_CALL_LOG, RECORD_AUDIO, ACCESS_FINE_LOCATION, GET_ACCOUNTS, READ_CONTACTS, WRITE_SETTINGS, READ/WRITE_EXTERNAL_STORAGE, INTERNET, RECEIVE_BOOT_COMPLETED, and more.
This permission combination enables surveillance, persistence, and exfiltration a hallmark of APT‑grade mobile malware.

Infrastructure Awareness: IOC Table for Defensive Blocking
Organizations should proactively block and alert on the following Indicators of Compromise associated with this APK and similar Donot APT mobile tooling.
Note: No live malicious domains or IPs are provided. This table is safe and awareness‑oriented.
| IOC Type | Value | Description |
|---|---|---|
| File Hash (MD5) | 242e05f06544349256470110fdb433b5 | Malicious APK identifier |
| File Hash (SHA1) | 0efd8ab6d9ad4d2dc5ad072bdbbd6a9cf15b9a41 | Cross‑tool integrity reference |
| File Hash (SHA256) | 70df22a25cbb8715f1d3dd693123ac92203b3a27dfc6c7fa0e48239cf15cbf02 | Strong cryptographic IOC |
| Package Name | Suspicious WeChat‑themed package | Used for masquerading |
| Behavior Pattern | SMS/Call log harvesting | Surveillance indicator |
| Behavior Pattern | Device location exfiltration | Tracking indicator |
| Behavior Pattern | Base64‑decoded file writes | Possible payload staging |
| Behavior Pattern | Remote server connection attempts | C2 communication attempts |
Why This Matters to Your Organization
Mobile devices are now primary endpoints for executives, diplomats, journalists, and government employees. APT groups especially Donot continue to weaponize fake productivity or communication apps to infiltrate high‑value targets.
Our Android Malware Forensics & Threat Infrastructure Mapping Service provides:
- Deep mobile malware reverse engineering
- Attacker infrastructure mapping
- IOC enrichment & detection engineering
- Threat attribution intelligence
- Executive‑level risk reports
- Defensive hardening recommendations
Protect Your Mobile Fleet Before APTs Target It
If your organization relies heavily on Android devices, now is the time to strengthen mobile threat detection.
Our specialists can perform rapid triage, full forensic investigations, or continuous threat monitoring tailored to your environment.
Ready to safeguard your mobile ecosystem?
Contact Us Team for a full forensic assessment today.



