Espionage-focused hacker group, Bitter APT, allegedly targets RAB
Skip to main content
  • Home
  • Economy
  • Stocks
  • Analysis
  • World+Biz
  • Sports
  • Features
  • Epaper
  • More
    • Subscribe
    • COVID-19
    • Bangladesh
    • Splash
    • Videos
    • Games
    • Long Read
    • Infograph
    • Interviews
    • Offbeat
    • Thoughts
    • Podcast
    • Quiz
    • Tech
    • Archive
    • Trial By Trivia
    • Magazine
    • Supplement
  • বাংলা
The Business Standard

Tuesday
July 05, 2022

Sign In
Subscribe
  • Home
  • Economy
  • Stocks
  • Analysis
  • World+Biz
  • Sports
  • Features
  • Epaper
  • More
    • Subscribe
    • COVID-19
    • Bangladesh
    • Splash
    • Videos
    • Games
    • Long Read
    • Infograph
    • Interviews
    • Offbeat
    • Thoughts
    • Podcast
    • Quiz
    • Tech
    • Archive
    • Trial By Trivia
    • Magazine
    • Supplement
  • বাংলা
TUESDAY, JULY 05, 2022
Espionage-focused hacker group, Bitter APT, allegedly targets RAB

Tech

TBS Report 
12 May, 2022, 10:15 am
Last modified: 12 May, 2022, 10:18 pm

Related News

  • Kushtia trader who set himself on fire at Press Club dies 
  • BB slaps 100% LC margin to discourage imports of cars, electronics among other items 
  • 2 Biman aircraft damaged at Dhaka airport 
  • Covid-19 infection almost doubled in Ctg in just 24hrs 
  • Covid deaths, cases again on the rise

Espionage-focused hacker group, Bitter APT, allegedly targets RAB

TBS Report 
12 May, 2022, 10:15 am
Last modified: 12 May, 2022, 10:18 pm
Photo: Collected
Photo: Collected

An espionage-focused hacker group, Bitter APT, known for targeting China, Pakistan, and Saudi Arabia, has allegedly added Bangladeshi government organisations to its list of targets.

The development comes as part of an ongoing campaign of Bitter Apt that commenced in August last year, reported a number of cybersecurity based news sites on Wednesday.

Bitter, aka APT-C-08 or T-APT-17, is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, with its prominent targets including the energy, engineering and government sectors.

As per the findings of cybersecurity firm Cisco Talos, the ongoing campaign targeted an elite unit of the Bangladesh government with a themed lure document alleging to relate to the regular operational tasks in the victim's organisation.  

The lure document is a spear-phishing email sent to high-ranking officers of the Rapid Action Battalion (RAB), Cisco Talos added,  saying that such emails contain either a malicious RTF document or a Microsoft Excel spreadsheet weaponized to exploit known vulnerabilities.

Photo: Collected from Cisco Talos
Photo: Collected from Cisco Talos

However, TBS tried to reach RAB high officials regarding this cyber-attack and did not get any comment on the matter.

ANM Imranuddin Khan, assistant director of RAB Legal & Media wing told TBS that their media wing director is out of the country now.

"We can't comment on the issue right now. Once he is back in the country he can comment," added Imranuddin.

TBS also tried to contact RAB Deputy Director Major Roisul Azam about the issue, but he was unavailable for comment.

The originating IP address and header information indicated that the emails were sent from mail servers based in Pakistan and the actor spoofed the sender details to make the email appear as though it was sent from Pakistani government organisations.

Cisco Talos compiled a list of fake sender email addresses from this campaign.

Once the victim opens the maldoc, the Equation Editor application is automatically launched to run the embedded objects containing the shellcode to exploit known vulnerabilities described as CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802 – all in Microsoft Office – which then download the trojan from the hosting server and run it on the victim's machine.

The trojan masquerades as a Windows Security update service and allows the malicious actor to perform remote code execution, opening the door to other activities by installing other tools. In this campaign, the trojan runs itself but the actor has other RATs and downloaders in their arsenal.

Photo: Collected from Cisco Talos
Photo: Collected from Cisco Talos

The cyber security firm commented that such surveillance campaigns could allow threat actors to access the organisation's confidential information and give their handlers an advantage over their competitors, regardless of whether they are state-sponsored.

"Bangladesh fits the profile we have defined for this threat actor, previously targeting Southeast Asian countries including China, Pakistan, and Saudi Arabia," Vitor Ventura, lead security researcher at Cisco Talos (EMEA and Asia), was quoted as saying by The Hacker News.

"And now, in this latest campaign, they have widened their reach to Bangladesh. Any new country in southeast Asia being targeted by Bitter APT shouldn't be of surprise," he added.

The cybersecurity expert said that the actors (hackers) often change their tools to avoid detection or attribution and this is part of the lifecycle of a threat actor showing its capability and determination.

Photo: Collected from Cisco Talos
Photo: Collected from Cisco Talos

As is typically observed in other social engineering attacks of this kind, the missives are designed to lure the recipients into opening a weaponised RTF document or a Microsoft Excel spreadsheet that exploits previously known flaws in the software to deploy a new trojan dubbed "ZxxZ."

ZxxZ, named so after a separator used by the malware when sending information back to the C2 server, is a 32-bit Windows executable compiled in Visual C++.

While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence, wrote The Hacker News.

Bangladesh / Top News

Bangladesh / Cybersecurity / Cyber attack / Hackers / Hacking

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • Padma Bridge opens up investment spree in south
    Padma Bridge opens up investment spree in south
  • BB slaps 100% LC margin to discourage imports of cars, electronics among other items 
    BB slaps 100% LC margin to discourage imports of cars, electronics among other items 
  • Several law enforcement departments monitor the scene of a mass shooting at a Fourth of July parade route in the wealthy Chicago suburb of Highland Park, Illinois, US July 4, 2022. REUTERS/Max Herman
    Suspect captured in shooting at 4 July parade in Chicago's Highland Park suburb

MOST VIEWED

  • Photo: PR
    MiHCM, Tech One Global join hands with Green Delta Insurance
  • Xiaomi brings customised smartphone for Bangladesh market
    Xiaomi brings customised smartphone for Bangladesh market
  • China’s quest for a competitive domestic operating system has been going on for decades. Microsoft Windows leads the market with an 85 per cent share in mainland China. Photo: Reuters
    China doubles down on domestic operating systems to cut reliance on foreign systems
  • A Tesla sign is seen at its factory in Shanghai, China, May 13, 2021. REUTERS/Aly Song
    Tesla hit by new lawsuit alleging racial abuse against Black workers
  • The Google logo is seen on on the company's European headquarters in Dublin, Ireland, February 27, 2021. REUTERS/Clodagh Kilcoyne
    Google to pay $90 mln to settle legal fight with app developers
  • Silhouette of mobile user is seen next to a screen projection of Apple logo in this picture illustration taken March 28, 2018. REUTERS/Dado Ruvic/Illustration
    Apple hikes Japan price of iPhone by nearly a fifth

Related News

  • Kushtia trader who set himself on fire at Press Club dies 
  • BB slaps 100% LC margin to discourage imports of cars, electronics among other items 
  • 2 Biman aircraft damaged at Dhaka airport 
  • Covid-19 infection almost doubled in Ctg in just 24hrs 
  • Covid deaths, cases again on the rise

Features

Last month Swapan Kumar Biswas, the acting principal of Mirzapur United College, was forced to wear a garland of shoes for ‘hurting religious sentiments.’ Photo: Collected

Where do teachers rank in our society?

22h | Panorama
Japanese Ambassador Naoki Ito. Sketch: TBS

'The game-changing projects are in line with the Bay of Bengal Industrial Growth Belt initiative'

1d | Panorama
A Glittery Eid

A Glittery Eid

1d | Mode
Rise’s target customers are people who crave to express themselves through what they wear, and their clothing line is not relegated to any age range.

Level up your Eid game with Rise

1d | Mode

More Videos from TBS

Realme Narzo 50A Prime available now

Realme Narzo 50A Prime available now

12h | Videos
Export products to get diversified

Export products to get diversified

13h | Videos
Horrible routes of human trafficking

Horrible routes of human trafficking

14h | Videos
Why Mbappe cheated Real Madrid

Why Mbappe cheated Real Madrid

15h | Videos

Most Read

1
TBS Illustration
Education

Universities may launch online classes again after Eid

2
Meet the man behind 'Azke amar mon balo nei'
Splash

Meet the man behind 'Azke amar mon balo nei'

3
Padma Bridge from satellite. Photo: Screengrab
Bangladesh

Padma Bridge from satellite 

4
World Bank to give Bangladesh $18b IDA loans in next five years
Economy

World Bank to give Bangladesh $18b IDA loans in next five years

5
Illustration: TBS
Interviews

‘No Bangladeshi company has the business model for exporting agricultural product’

6
Lee Hyun-seung (third from right), head of Korea Expressway Corp.'s Overseas Project Division, shakes hands with Quazi Muhammad Ferdous, head of the Bridge Authority of Bangladesh, after signing a contract on June 29 (local time).
Bangladesh

Korean company to oversee N8 Expressway in Bangladesh

EMAIL US
contact@tbsnews.net
FOLLOW US
WHATSAPP
+880 1847416158
The Business Standard
  • About Us
  • Contact us
  • Sitemap
  • Privacy Policy
  • Comment Policy
Copyright © 2022
The Business Standard All rights reserved
Technical Partner: RSI Lab
BENEATH THE SURFACE
Workers ready a passenger vessel with a fresh coat of paint to the deck ahead of the Eid-ul-Azha at a dockyard at Mirerbagh in South Keraniganj. The vessel getting the makeover plies the Bhandaria route and will take holidaying people from the city to their country homes. Eid will be celebrated on 10 June this year. The photo was taken on Monday. Photo: Mumit M

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net