Beware the Fake Chat: DONOT Team’s Sneaky Spy Apps Targeting India!
The DONOT Team strikes again! This notorious advanced persistent threat group is using the Tanzeem apps to conduct intelligence-gathering operations, targeting individuals in India. These apps masquerade as chat tools, but once installed, they access sensitive information. It’s a spy story with a tech twist!

Hot Take:
In the world of cybersecurity, the DONOT Team is like that nosy neighbor who just can’t help but peek through your windows. They’re not interested in borrowing sugar; they’re here for your data. With apps that promise chat but deliver espionage, it’s clear they’re not the friendly type. Lesson learned: in the digital world, trust no app, especially if it sounds too chatty to be true.
Key Points:
- DONOT Team uses two Android apps, “Tanzeem” and “Tanzeem Update,” for intelligence operations targeting Indian individuals and groups.
- The apps falsely present themselves as chat applications but instead exploit Android features to collect data.
- Once installed, the apps request accessibility permissions to access call logs, contacts, files, and even track device location.
- The apps use push notifications to prompt users into installing further malicious payloads, ensuring persistence.
- DONOT Team has been active since 2016, targeting organizations in South Asia with sophisticated malware.
Already a member? Log in here