Espionage-focused hacker group, Bitter APT, allegedly targets RAB | The Business Standard
Skip to main content
  • Latest
  • Economy
    • Banking
    • Stocks
    • Industry
    • Analysis
    • Bazaar
    • RMG
    • Corporates
    • Aviation
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
The Business Standard

Wednesday
July 02, 2025

Sign In
Subscribe
  • Latest
  • Economy
    • Banking
    • Stocks
    • Industry
    • Analysis
    • Bazaar
    • RMG
    • Corporates
    • Aviation
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
WEDNESDAY, JULY 02, 2025
Espionage-focused hacker group, Bitter APT, allegedly targets RAB

Tech

TBS Report 
12 May, 2022, 10:15 am
Last modified: 12 May, 2022, 10:18 pm

Related News

  • Dengue claims one more life; 416 hospitalised in 24hrs
  • Tarique Rahman urges BNP leaders to remain vigilant against conspiracies
  • Ctg Port’s NCT to run with existing workforce; Navy may oversee operations
  • The economy in FY25: Battling challenging times
  • No anti-state agreements will be signed: Shipping adviser

Espionage-focused hacker group, Bitter APT, allegedly targets RAB

TBS Report 
12 May, 2022, 10:15 am
Last modified: 12 May, 2022, 10:18 pm
Photo: Collected
Photo: Collected

An espionage-focused hacker group, Bitter APT, known for targeting China, Pakistan, and Saudi Arabia, has allegedly added Bangladeshi government organisations to its list of targets.

The development comes as part of an ongoing campaign of Bitter Apt that commenced in August last year, reported a number of cybersecurity based news sites on Wednesday.

Bitter, aka APT-C-08 or T-APT-17, is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, with its prominent targets including the energy, engineering and government sectors.

The Business Standard Google News Keep updated, follow The Business Standard's Google news channel

As per the findings of cybersecurity firm Cisco Talos, the ongoing campaign targeted an elite unit of the Bangladesh government with a themed lure document alleging to relate to the regular operational tasks in the victim's organisation.  

The lure document is a spear-phishing email sent to high-ranking officers of the Rapid Action Battalion (RAB), Cisco Talos added,  saying that such emails contain either a malicious RTF document or a Microsoft Excel spreadsheet weaponized to exploit known vulnerabilities.

Photo: Collected from Cisco Talos
Photo: Collected from Cisco Talos

However, TBS tried to reach RAB high officials regarding this cyber-attack and did not get any comment on the matter.

ANM Imranuddin Khan, assistant director of RAB Legal & Media wing told TBS that their media wing director is out of the country now.

"We can't comment on the issue right now. Once he is back in the country he can comment," added Imranuddin.

TBS also tried to contact RAB Deputy Director Major Roisul Azam about the issue, but he was unavailable for comment.

The originating IP address and header information indicated that the emails were sent from mail servers based in Pakistan and the actor spoofed the sender details to make the email appear as though it was sent from Pakistani government organisations.

Cisco Talos compiled a list of fake sender email addresses from this campaign.

Once the victim opens the maldoc, the Equation Editor application is automatically launched to run the embedded objects containing the shellcode to exploit known vulnerabilities described as CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802 – all in Microsoft Office – which then download the trojan from the hosting server and run it on the victim's machine.

The trojan masquerades as a Windows Security update service and allows the malicious actor to perform remote code execution, opening the door to other activities by installing other tools. In this campaign, the trojan runs itself but the actor has other RATs and downloaders in their arsenal.

Photo: Collected from Cisco Talos
Photo: Collected from Cisco Talos

The cyber security firm commented that such surveillance campaigns could allow threat actors to access the organisation's confidential information and give their handlers an advantage over their competitors, regardless of whether they are state-sponsored.

"Bangladesh fits the profile we have defined for this threat actor, previously targeting Southeast Asian countries including China, Pakistan, and Saudi Arabia," Vitor Ventura, lead security researcher at Cisco Talos (EMEA and Asia), was quoted as saying by The Hacker News.

"And now, in this latest campaign, they have widened their reach to Bangladesh. Any new country in southeast Asia being targeted by Bitter APT shouldn't be of surprise," he added.

The cybersecurity expert said that the actors (hackers) often change their tools to avoid detection or attribution and this is part of the lifecycle of a threat actor showing its capability and determination.

Photo: Collected from Cisco Talos
Photo: Collected from Cisco Talos

As is typically observed in other social engineering attacks of this kind, the missives are designed to lure the recipients into opening a weaponised RTF document or a Microsoft Excel spreadsheet that exploits previously known flaws in the software to deploy a new trojan dubbed "ZxxZ."

ZxxZ, named so after a separator used by the malware when sending information back to the C2 server, is a 32-bit Windows executable compiled in Visual C++.

While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence, wrote The Hacker News.

Bangladesh / Top News

Bangladesh / Cybersecurity / Cyber attack / Hackers / Hacking

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • The economy in FY25: Battling challenging times
    The economy in FY25: Battling challenging times
  • Police produce former chief election commissioner Nurul Huda in court on 1 July 2025. File Photo: TBS
    'It was beyond my control': Ex-CEC Nurul Huda on his role in 2018 national polls
  • Protesters block road in front of the Chattogram range deputy inspector general’s (DIG) office on 2 July 2025. Photo: TBS
    Patiya clash: Protesters block road in front of DIG office, demand removal of OC

MOST VIEWED

  • Showkat Ali Chowdhury, the chairman of Eastern Bank Limited (EBL). File photo
    Bank accounts of Eastern Bank chairman, his family frozen
  • Hazrat Shahjalal International Airport in Dhaka. Photo: Zia Chowdhury
    Airport officials instructed to pay close attention during baggage screening for all VIP and VVIP passengers
  • Govt lowers interest rates on savings instruments
    Govt lowers interest rates on savings instruments
  • The Standard Chartered bank logo is seen at their headquarters in London, Britain, July 26, 2022. Photo: REUTERS/Peter Nicholls/File Photo
    Standard Chartered Bank faces $2.7 billion lawsuit over alleged role in 1MDB fraud
  • File photo of Bangladesh Public Service Commission logo. Photo: Collected
    Repeat recommendations in 44th BCS spark vacancy fears
  • File photo of Chattogram Port/TBS
    Ctg port handles record 32.96 lakh containers in FY25, revenue hits Tk75,432 crore

Related News

  • Dengue claims one more life; 416 hospitalised in 24hrs
  • Tarique Rahman urges BNP leaders to remain vigilant against conspiracies
  • Ctg Port’s NCT to run with existing workforce; Navy may oversee operations
  • The economy in FY25: Battling challenging times
  • No anti-state agreements will be signed: Shipping adviser

Features

Illustration: TBS

Ulan Daspara: Remnants of a fishing village in Dhaka

1d | Panorama
Photo: Collected

Innovative storage accessories you’ll love

3d | Brands
Two competitors in this segment — one a flashy newcomer, the other a hybrid veteran — are going head-to-head: the GAC GS3 Emzoom and the Toyota CH-R. PHOTOS: Nafirul Haq (GAC Emzoom) and Akif Hamid (Toyota CH-R)

GAC Emzoom vs Toyota CH-R: The battle of tech vs trust

3d | Wheels
Women farmers, deeply reliant on access to natural resources for both farming and domestic survival, are among the most affected, caught between ecological collapse and inadequate structural support. Photo: Shaharin Amin Shupty

Hope in the hills: How women farmers in Bandarban are weathering the climate crisis

2d | Panorama

More Videos from TBS

What are the political parties saying after the meeting?

What are the political parties saying after the meeting?

46m | TBS Today
Bangladesh no longer owes India's Adani Power any more

Bangladesh no longer owes India's Adani Power any more

56m | TBS Today
Ukraine Can Still Win, how?

Ukraine Can Still Win, how?

36m | Others
Financial advisor calls for increased use of technology in SME sector

Financial advisor calls for increased use of technology in SME sector

1h | TBS Today
EMAIL US
contact@tbsnews.net
FOLLOW US
WHATSAPP
+880 1847416158
The Business Standard
  • About Us
  • Contact us
  • Sitemap
  • Advertisement
  • Privacy Policy
  • Comment Policy
Copyright © 2025
The Business Standard All rights reserved
Technical Partner: RSI Lab

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net