Danti is an advanced persistent threat actor active since at least 2015 and primarily associated with cyberespionage against Indian government and diplomatic organizations. The group has also been observed targeting other countries in Asia, including Kazakhstan, Kyrgyzstan, Uzbekistan, Myanmar, Nepal, and the Philippines. Danti is assessed to be probably related to DragonOK and NetTraveller, and some reporting notes overlap with SPIVY- or SPLM-adjacent activity and PotPlayer-based DLL side-loading tradecraft. Danti is known for spear-phishing operations delivering malicious Microsoft Office documents, including DOCX and Web Archive-based lures, to achieve initial access. A notable cluster of activity in 2016 used the Microsoft Office EPS vulnerability CVE-2015-2545 with custom shellcode embedded in decoy documents. The actor targeted Indian diplomatic entities, including embassies and organizations linked to the Ministry of External Affairs and Foreign Service Institute. In at least one later wave, the operation appeared to leverage a compromised Indian government email account to distribute malicious attachments. Post-exploitation tradecraft attributed to Danti includes deployment of custom backdoors, use of legitimate signed software for DLL side-loading, and encrypted command-and-control communications. One documented infection chain used a self-extracting archive together with a legitimate PotPlayer executable to side-load a malicious DLL and install a backdoor capable of system profiling, task retrieval, and remote control functions. Reported backdoor capabilities include collection of host information and execution of common remote-administration tasks such as file, process, and service operations, upload and download, and interactive shell access. Danti is best characterized as a targeted espionage actor focused on government and diplomatic intelligence collection in South and Central Asia. Its operations show sustained use of phishing-based initial access, exploit-enabled document delivery, persistence through side-loading, and modular backdoor deployment consistent with long-term intelligence gathering rather than disruptive or financially motivated activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an activity cluster with observed overlap in victim environments/targeting alongside Sofacy SPLM activity; no further operational detail provided in the content.
One of multiple APT groups reported exploiting CVE-2015-2545 via crafted EPS files to achieve code execution.
APT actor primarily targeting Indian government/diplomatic entities (with additional activity across Central/Southeast Asia) using spear-phishing DOCX/EPS exploitation (CVE-2015-2545) and custom loaders/backdoors; assessed in-report as probably related to NetTraveller and DragonOK tool/functionality.
Referenced as an actor with malware/tradecraft overlap to TA428, including PotPlayerMini DLL side-loading and related malware in a Kazakhstan-targeting case.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.