YTY is a custom Windows malware framework associated with DoNot Team, also tracked as APT-C-35. It is used in long-running cyberespionage operations primarily targeting government, military, foreign affairs, and embassy entities, with a concentration in South Asia and later observed targeting a European diplomatic organization. The framework’s primary purpose is collection and exfiltration of victim data.
YTY is best characterized as a modular backdoor framework. Reported tradecraft indicates a staged infection chain in which malicious Microsoft Office documents delivered through spearphishing deploy Windows malware derived from the YTY framework. The framework includes downloader components that ultimately install a minimally featured backdoor capable of retrieving and executing additional modules. Related DoNot operations have also used malicious archives and disguised executables, but the supplied facts most directly tie YTY itself to spearphishing and malicious document delivery.
Observed YTY capabilities include host reconnaissance and surveillance. It can enumerate running processes using tasklist, discover remote systems with net view, collect the victim username, gather network and domain information via ipconfig /all, capture screenshots, log keystrokes through a keylogger plugin, and collect files matching document- and contact-oriented extensions for return to command-and-control infrastructure. Persistence has been established through Windows Scheduled Tasks created with schtasks. YTY has also been reported to communicate with command-and-control by retrieving content from Google Docs, reflecting DoNot’s use of trusted web services to blend malicious traffic with normal activity.
The framework has been linked to variants including Gedit and DarkMusical. DarkMusical was used against military organizations in Bangladesh and Nepal. Across reporting, YTY and its derivatives are consistently associated with espionage-focused collection rather than disruptive or destructive effects.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET researchers have traced several campaigns that leverage Windows malware derived from the group’s signature yty malware framework. The main purpose of the “yty” malware framework is to collect and exfiltrate data.
DoNot APT is known for using custom-built Windows malware, including backdoors like YTY and GEdit, often delivered through spear-phishing emails or malicious documents.
DoNot APT is known for using custom-built Windows malware, including backdoors like YTY and GEdit, often delivered through spear-phishing emails or malicious documents.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
According to ESET telemetry, Donot Team has been consistently targeting the same entities with waves of spearphishing emails every two to four months.
According to ESET telemetry, Donot Team has been consistently targeting the same entities with waves of spearphishing emails every two to four months. The spearphishing emails have malicious Microsoft Office documents attached that the attackers use to deploy their malware.
“...downloads from [1] to [3], modifies 3 first bytes back to their original form. This technique is used to evade security solutions and keep them from scanning the executable.”
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
“...fetch a malicious remote template from its C2 by sending an HTTP GET request... The first message to the server is sent as a POST request...”
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom Windows backdoor associated with DoNot APT and mentioned as part of the group's known malware toolkit.
A custom-built Windows backdoor used by DoNot Team.
A modular Windows spyware/backdoor framework attributed to the DoNot Team, delivered via spearphishing and macro/RTF-based execution, using staged shellcode loaders and multiple DLL modules for data theft and remote access (keylogging, screenshots, file collection, browser credential/history theft, file upload, and reverse shell). Uses scheduled tasks for persistence and AES-256/Base64 for C2 communications; can fetch updated C2 addresses via Google Drive.
Backdoor that collects the victim username.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.