Danti is a cybercrime group that first surfaced in 2016, and their activity has been relatively low ever since. The group appears to share characteristics, tools, and infrastructure with famous Chinese Advanced Persistent Threat (APT) groups, but cybersecurity experts cannot confirm that the members of Danti are based in China.
The group's activity spread across Nepal, Philippines, Myanmar, Kazakhstan and Uzbekistan. Their targets include, but are not restricted to: government officials, political movements and diplomatic missions. The group has been found to use a wide range of public tools and custom-made backdoors to execute their attacks. It appears that the ultimate goal of their campaigns is to gain illicit access to classified data, so it is secure to assume that cyber espionage is Danti's specialty.
The group's attacks are carried out via spear-phishing emails that contain a corrupted file attachment almost exclusively. During their first campaigns, the group relies on the CVE-2015-2545 vulnerability that enabled EPS image files to execute remote code on an unsecured host – however, it is likely that Danti has expanded its arsenal of vulnerabilities during the past few years.
Companies and organizations are the prime targets of groups like Danti, and they should take the necessary measures to protect their network infrastructure from vicious attacks. This requires the use of up-to-date software and operating systems, as well as relying on the security services offered by top-of-the-shelf anti-virus products.
Use SpyHunter to Detect and Remove PC Threats
If you are concerned that malware or PC threats similar to Danti may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.
Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.