Espionage-focused hacker group, Bitter APT, allegedly targets RAB | The Business Standard
Skip to main content
  • Epaper
  • Economy
    • Aviation
    • Banking
    • Bazaar
    • Budget
    • Industry
    • NBR
    • RMG
    • Corporates
  • Stocks
  • Analysis
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
The Business Standard

Saturday
May 24, 2025

Sign In
Subscribe
  • Epaper
  • Economy
    • Aviation
    • Banking
    • Bazaar
    • Budget
    • Industry
    • NBR
    • RMG
    • Corporates
  • Stocks
  • Analysis
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
SATURDAY, MAY 24, 2025
Espionage-focused hacker group, Bitter APT, allegedly targets RAB

Tech

TBS Report 
12 May, 2022, 10:15 am
Last modified: 12 May, 2022, 10:18 pm

Related News

  • Private airlines for urgent reform of aviation regulations
  • Where did Bangladesh’s leftist parties go?
  • Ecnec approves two power projects worth Tk4,671cr
  • Inflation eased in April due to monetary, fiscal measures: Planning Commission report
  • 'Couldn’t meet CA despite trying for days': Factions within govt positioned BNP as opponent, Salahuddin tells Jamuna

Espionage-focused hacker group, Bitter APT, allegedly targets RAB

TBS Report 
12 May, 2022, 10:15 am
Last modified: 12 May, 2022, 10:18 pm
Photo: Collected
Photo: Collected

An espionage-focused hacker group, Bitter APT, known for targeting China, Pakistan, and Saudi Arabia, has allegedly added Bangladeshi government organisations to its list of targets.

The development comes as part of an ongoing campaign of Bitter Apt that commenced in August last year, reported a number of cybersecurity based news sites on Wednesday.

Bitter, aka APT-C-08 or T-APT-17, is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, with its prominent targets including the energy, engineering and government sectors.

The Business Standard Google News Keep updated, follow The Business Standard's Google news channel

As per the findings of cybersecurity firm Cisco Talos, the ongoing campaign targeted an elite unit of the Bangladesh government with a themed lure document alleging to relate to the regular operational tasks in the victim's organisation.  

The lure document is a spear-phishing email sent to high-ranking officers of the Rapid Action Battalion (RAB), Cisco Talos added,  saying that such emails contain either a malicious RTF document or a Microsoft Excel spreadsheet weaponized to exploit known vulnerabilities.

Photo: Collected from Cisco Talos
Photo: Collected from Cisco Talos

However, TBS tried to reach RAB high officials regarding this cyber-attack and did not get any comment on the matter.

ANM Imranuddin Khan, assistant director of RAB Legal & Media wing told TBS that their media wing director is out of the country now.

"We can't comment on the issue right now. Once he is back in the country he can comment," added Imranuddin.

TBS also tried to contact RAB Deputy Director Major Roisul Azam about the issue, but he was unavailable for comment.

The originating IP address and header information indicated that the emails were sent from mail servers based in Pakistan and the actor spoofed the sender details to make the email appear as though it was sent from Pakistani government organisations.

Cisco Talos compiled a list of fake sender email addresses from this campaign.

Once the victim opens the maldoc, the Equation Editor application is automatically launched to run the embedded objects containing the shellcode to exploit known vulnerabilities described as CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802 – all in Microsoft Office – which then download the trojan from the hosting server and run it on the victim's machine.

The trojan masquerades as a Windows Security update service and allows the malicious actor to perform remote code execution, opening the door to other activities by installing other tools. In this campaign, the trojan runs itself but the actor has other RATs and downloaders in their arsenal.

Photo: Collected from Cisco Talos
Photo: Collected from Cisco Talos

The cyber security firm commented that such surveillance campaigns could allow threat actors to access the organisation's confidential information and give their handlers an advantage over their competitors, regardless of whether they are state-sponsored.

"Bangladesh fits the profile we have defined for this threat actor, previously targeting Southeast Asian countries including China, Pakistan, and Saudi Arabia," Vitor Ventura, lead security researcher at Cisco Talos (EMEA and Asia), was quoted as saying by The Hacker News.

"And now, in this latest campaign, they have widened their reach to Bangladesh. Any new country in southeast Asia being targeted by Bitter APT shouldn't be of surprise," he added.

The cybersecurity expert said that the actors (hackers) often change their tools to avoid detection or attribution and this is part of the lifecycle of a threat actor showing its capability and determination.

Photo: Collected from Cisco Talos
Photo: Collected from Cisco Talos

As is typically observed in other social engineering attacks of this kind, the missives are designed to lure the recipients into opening a weaponised RTF document or a Microsoft Excel spreadsheet that exploits previously known flaws in the software to deploy a new trojan dubbed "ZxxZ."

ZxxZ, named so after a separator used by the malware when sending information back to the C2 server, is a 32-bit Windows executable compiled in Visual C++.

While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence, wrote The Hacker News.

Bangladesh / Top News

Bangladesh / Cybersecurity / Cyber attack / Hackers / Hacking

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • BNP senior leaders and CA at Jamuna on 24 May evening. Photo: CA Press Wing
    Talks with CA: BNP calls for swift completion of reforms for elections in Dec, removal of 'controversial' advisers
  • Jamaat-e-Islami Ameer Shafiqur Rahman and Jamaat Nayeb-e-Ameer Syed Abdullah Muhammad Taher meet Chief Adviser Muhammad Yunus on 24 May. Photo: CA Press Wing
    Jamaat in favour of elections by Feb or just after Ramadan: Ameer Shafiqur
  • A six-member delegation, led by Convener Nahid Islam, met Chief Adviser Muhammad Yunus at the State Guest House, Jamuna on 24 May 2025. Photo: CA Press Wing
    Talks with CA: NCP seeks specific roadmap for elections, reforms and justice

MOST VIEWED

  • Five political parties hold meeting at the office of Inslami Andolan on 22 May 2025. Photo: Courtesy
    5 parties, including NCP and Jamaat, agree to support Yunus-led govt to hold polls after reforms
  • The Advisory Council of the interim government holds a meeting at the state guest house Jamuna in Dhaka on 10 May 2025. Photo: PID
    What CA Yunus discussed with Advisory Council about 'resignation'
  • Representational image/Wikipedia
    Bangladesh cancels $21 million deal with Indian shipbuilding firm: Reports
  • Chief Adviser Professor Muhammad Yunus presides over a meeting of ECNEC at the Planning Commission office on 24 May 2025. Photo: CA Press Wing
    CA Yunus is not resigning; we are not leaving: Planning adviser after closed-door meeting
  • Faiz Ahmad Tayeb. Photo: BSS
    CA Yunus will not resign: Special Assistant Taiyeb
  • Infographic: TBS
    Dhaka's traffic crisis needs $59b solution by 2045, estimates new strategy

Related News

  • Private airlines for urgent reform of aviation regulations
  • Where did Bangladesh’s leftist parties go?
  • Ecnec approves two power projects worth Tk4,671cr
  • Inflation eased in April due to monetary, fiscal measures: Planning Commission report
  • 'Couldn’t meet CA despite trying for days': Factions within govt positioned BNP as opponent, Salahuddin tells Jamuna

Features

The well has a circular opening, approximately ten feet wide. It is inside the house once known as Shakti Oushadhaloy. Photo: Saleh Shafique

The last well in Narinda: A water source older and purer than Wasa

1d | Panorama
The way you drape your shari often depends on your blouse; with different blouses, the style can be adapted accordingly.

Different ways to drape your shari

1d | Mode
Shantana posing with the students of Lalmonirhat Taekwondo Association (LTA), which she founded with the vision of empowering rural girls through martial arts. Photo: Courtesy

They told her not to dream. Shantana decided to become a fighter instead

3d | Panorama
Football presenter Gary Lineker walks outside his home, after resigning from the BBC after 25 years of presenting Match of the Day, in London, Britain. Photo: Reuters

Gary Lineker’s fallout once again exposes Western media’s selective moral compass on Palestine

3d | Features

More Videos from TBS

NCP Insists on Clear Election Plan, Reforms, and Justice

NCP Insists on Clear Election Plan, Reforms, and Justice

1h | Podcast
What are the thoughts of BNP and other political parties on the capital market?

What are the thoughts of BNP and other political parties on the capital market?

2h | TBS Today
News of The Day, 24 MAY 2025

News of The Day, 24 MAY 2025

3h | TBS News of the day
90 days are coming to an end, Trump's hopes have not been fulfilled

90 days are coming to an end, Trump's hopes have not been fulfilled

36m | Others
EMAIL US
contact@tbsnews.net
FOLLOW US
WHATSAPP
+880 1847416158
The Business Standard
  • About Us
  • Contact us
  • Sitemap
  • Advertisement
  • Privacy Policy
  • Comment Policy
Copyright © 2025
The Business Standard All rights reserved
Technical Partner: RSI Lab

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net