An India-nexus threat actor targeting German government entities with spear phishing and Android malware.
Analyst brief
VICEROY TIGER is a threat actor with an India nexus, known by aliases such as OPERATION HANGOVER and Donot Team. It primarily targets government, administration, and security service entities in Germany. The actor's key TTPs include spear phishing emails with malicious Microsoft Office documents, Android platform-targeting malware, and credential harvesting phishing activities. Defenders should prioritize monitoring for spear phishing emails, enhance mobile security measures, and track credential harvesting attempts from suspicious domains.
VICEROY TIGER
OPERATION HANGOVERDonot TeamAPT-C-35
unknown
VICEROY TIGER is an adversary with a nexus to India that has historically targeted entities throughout multiple sectors. Older activity targeted multiple sectors and countries; however, since 2015 this adversary appears to focus on entities in Pakistan with a particular focus on government and security organizations. This adversary consistently leverages spear phishing emails containing malicious Microsoft Office documents, malware designed to target the Android mobile platform, and phishing activity designed to harvest user credentials. In March 2017, the 360 Chasing Team found a sample of targeted attacks that confirmed the previously unknown sample of APT's attack actions, which the organization can now trace back at least in April 2016. The chasing team named the attack organization APT-C-35. In June 2017, the 360 Threat Intelligence Center discovered the organization’s new attack activity, confirmed and exposed the gang’s targeted attacks against Pakistan, and analyzed in detail. The unique EHDevel malicious code framework used by the organization.
What methods does VICEROY TIGER use to attack its targets?+
VICEROY TIGER primarily uses spear phishing emails with malicious Microsoft Office documents, malware targeting the Android platform, and phishing activity designed to harvest user credentials.
Which country has VICEROY TIGER primarily focused on in its latest activities?+
Since 2015, this adversary appears to focus on entities in Pakistan, particularly government and security organizations.