YTY is a modular Windows backdoor framework used by Donot Team, also known as APT-C-35 and SectorE02, for cyberespionage and sensitive-data collection. Its deployment chain consists of downloaders that ultimately install a minimally functional backdoor responsible for downloading and executing additional components. YTY-derived variants include Gedit and DarkMusical. Campaigns have targeted government, military, foreign affairs, and diplomatic organizations, primarily in Pakistan, Bangladesh, Sri Lanka, and Nepal, as well as these countries’ embassies abroad.
YTY is delivered through spearphishing emails carrying malicious Microsoft Office documents. An observed campaign used a Kashmir-themed document exploiting CVE-2017-8570 to execute a downloader and deploy the framework. Persistence is established through Windows scheduled tasks. Analyzed implementations include C++ downloaders, a C# backdoor, and separate collection plugins.
The framework supports keylogging, periodic screenshot capture, document discovery, and file exfiltration. Collection components enumerate fixed disks, record document metadata, and upload selected documents and outputs from other plugins to command-and-control servers. Reconnaissance includes collecting usernames, computer names, operating-system details, network configuration, domain information, running processes, and remote-system information using native Windows utilities such as tasklist, ipconfig, and net view.
YTY components retrieve command-and-control configuration from Google-hosted documents and retain hardcoded fallback addresses. Analyzed versions use AES-encrypted communications and reversed, Base64-encoded strings; earlier versions communicated in plaintext.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
发现的样本是名为kahsmir issue abida.doc的漏洞利用文档……最后通过CVE-2017-8570触发执行释放的恶意脚本,再通过脚本执行释放的EXE文件。
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
近期我们再次跟踪到该团伙利用较新的Office Nday漏洞发起的新的攻击活动,并对攻击中使用的yty框架最新的恶意代码进行了详细分析。
ESET researchers have traced several campaigns that leverage Windows malware derived from the group’s signature yty malware framework. The main purpose of the “yty” malware framework is to collect and exfiltrate data.
DoNot APT is known for using custom-built Windows malware, including backdoors like YTY and GEdit, often delivered through spear-phishing emails or malicious documents.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
According to ESET telemetry, Donot Team has been consistently targeting the same entities with waves of spearphishing emails every two to four months. The spearphishing emails have malicious Microsoft Office documents attached that the attackers use to deploy their malware.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
50 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom Windows backdoor associated with DoNot APT and mentioned as part of the group's known malware toolkit.
A custom-built Windows backdoor used by DoNot Team.
A modular Windows spyware/backdoor framework attributed to the DoNot Team, delivered via spearphishing and macro/RTF-based execution, using staged shellcode loaders and multiple DLL modules for data theft and remote access (keylogging, screenshots, file collection, browser credential/history theft, file upload, and reverse shell). Uses scheduled tasks for persistence and AES-256/Base64 for C2 communications; can fetch updated C2 addresses via Google Drive.
Backdoor that collects the victim username.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.