Thursday, April 25, 2024
HomeCyber CrimeBitter APT Hackers Continue to Target Bangladesh Military Entities

Bitter APT Hackers Continue to Target Bangladesh Military Entities

 

An advanced persistent threat known as Bitter has continued to target military organizations in Bangladesh with prolonged assaults.

 

In a recent report released on July 5, cybersecurity company SECUINFRA said that “threat actors undertake espionage by installing Remote Access Trojans through malicious document files and intermediary malware stages.”

 

The company’s research expands on a previous analysis from Cisco Talos published in May, which revealed the group’s expansion in targeting to hit Bangladeshi government entities using a backdoor known as ZxxZ. The company’s research has its headquarters in Berlin.

Bitter, also known by the codenames APT-C-08 and T-APT-17, has reportedly been active since at least late 2013 and has a history of deploying several tools, including BitterRAT and ArtraDownloader, to target Saudi Arabia, China, and Pakistan.

The most recent attack chain described by SECUINFRA is thought to have been carried out in mid-May 2022. It is thought to have started with a weaponized Excel document that was probably distributed via a spear-phishing email and, when opened, used the Microsoft Equation Editor exploit (CVE-2018-0798) to download the next-stage binary from a remote server.

 

The downloaded payload, ZxxZ (or MuuyDownloader by the Qi-Anxin Threat Intelligence Center), is implemented in Visual C++ and serves as a second-stage implant that enables the attacker to introduce further malware.

The most noticeable alteration in the malware is the substitution of an underscore for the “ZxxZ” separator used when transmitting data back to the command-and-control (C2) server, indicating that the organisation is actively making changes to its source code to avoid detection.

A backdoor known as Almond RAT, a.NET-based RAT that first surfaced in May 2022 and provides rudimentary data collecting capability and the ability to execute arbitrary instructions, is being utilised by the threat actor in its efforts. The infection also uses string encryption and obfuscation methods to avoid discovery and thwart analysis.

 

The researchers claimed that the major goals of almond RATs appeared to be file system detection, data exfiltration, and a mechanism to load other tools and create persistence. “The layout of the tools’ design seems to allow for rapid modification and adaptation to the present assault scenario.”

IEMA IEMLabs
IEMA IEMLabshttps://iemlabs.com
IEMLabs is an ISO 27001:2013 and ISO 9001:2015 certified company, we are also a proud member of EC Council, NASSCOM, Data Security Council of India (DSCI), Indian Chamber of Commerce (ICC), U.S. Chamber of Commerce, and Confederation of Indian Industry (CII). The company was established in 2016 with a vision in mind to provide Cyber Security to the digital world and make them Hack Proof. The question is why are we suddenly talking about Cyber Security and all this stuff? With the development of technology, more and more companies are shifting their business to Digital World which is resulting in the increase in Cyber Crimes.
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments

Izzi Казино онлайн казино казино x мобильді нұсқасы on Instagram and Facebook Video Download Made Easy with ssyoutube.com
Temporada 2022-2023 on CamPhish
2017 Grammy Outfits on Meesho Supplier Panel: Register Now!
React JS Training in Bangalore on Best Online Learning Platforms in India
DigiSec Technologies | Digital Marketing agency in Melbourne on Buy your favourite Mobile on EMI
亚洲A∨精品无码一区二区观看 on Restaurant Scheduling 101 For Better Business Performance

Write For Us