Sunday , August 30 2026
Nymaim

BD CIRT detected over 27,000 Nymaim/Avalanche Malware related events in BD

There has been a sharp rise in malware linked to the Nymaim / Avalanche loader in Bangladesh. CIRT BD observed over 27,000 malware events, which means bad actors are trying to infect systems and there is ongoing contact with the botnet.

Figure: Detected Nymaim / Avalanche- Nymaim Malware Communications from Bangladesh IP Addresses, BD CIRT

Threat Overview

Five Critical WordPress Flaws Lead to Site Takeover or RCE

Many serious security flaws have been found in WordPress plugins and themes, such as WPMU DEV Dashboard, Avada, TranslatePress, Pods,...
Read More
Five Critical WordPress Flaws Lead to Site Takeover or RCE

700 AI agents united to hack Hugging Face after breaking isolation

700 AI agents supposedly escaped their isolation, created a secret communication channel, and worked together to attack Hugging Face's systems....
Read More
700 AI agents united to hack Hugging Face after breaking isolation

ServiceNow warns of three critical security vulnerabilities

ServiceNow issued security updates for three new serious AI Platform problems that can be used in code injection, SQL injection,...
Read More
ServiceNow warns of three critical security vulnerabilities

100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

Over 100 tech, cybersecurity, and finance groups have signed an open letter with OpenAI. They want a global increase in...
Read More
100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

8.7 Million Customers data exposed from 3 Airports 

3 airports in the UK were affected by a "cyber security incident." Hackers got into data belonging to nearly nine...
Read More
8.7 Million Customers data exposed from 3 Airports 

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
Crack 85 Accounts and Steal 2,500+ Records  8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
270+ Zimbra servers compromised in continuous attacks

Singapore Approves 200MW Data-Centre Expansion Under Second Call

Singapore has picked four data-centre plans for a total of 200MW of power in its second Data Centre Call for...
Read More
Singapore Approves 200MW Data-Centre Expansion Under Second Call

Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages

Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
Chameleon SEO Poisoning  Hackers poison Bing and Google search results to deliver phishing banking pages

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

Nymaim (also known as Gozi ISFB Loader) is a multi-stage malware loader used to deploy additional malicious payloads, including:

Banking trojans
Credential stealers
Ransomware
Remote access tools (RATs)

The malware is highly adaptive, allowing attackers to update capabilities post-infection through command-and-control (C2) servers.

Key Findings in Bangladesh

27,000+ malware events detected
Activity across 20+ network providers (ASNs)
Multiple compromised hosts communicating with botnet servers
C2 communication captured via sinkhole monitoring

These signs show that there are infected devices in Bangladesh networks that are trying to reconnect with known harmful servers.

Targeted Data

Nymaim infections aim to steal sensitive information such as:

Banking credentials
Payment card data
System configuration details

This data is commonly used for

Financial fraud
Account takeovers
Identity theft
Secondary cyberattacks

Malware File Names Observed

Suspicious File Names:
update.exe
flashplayer_update.exe
svchost.exe
java_update.exe

Malicious Domains (examples):

g-update[.]net
secure-update[.]biz
update-service[.]org

Known Malicious IPs:
184.105.192[.]2
185.82.202[.]132
91.220.131[.]37

Behavioral Indicators:

Outbound HTTP/HTTPS traffic to unknown domains
Encrypted payload downloads
Activity in AppData/Temp directories

Organizations in Bangladesh are strongly advised to:

Block known malicious IPs and domains
Implement DNS sinkholing
Deploy Endpoint Detection & Response (EDR)
Monitor unusual DNS and HTTP traffic
Sandbox suspicious files and attachments
Continuously monitor networks for anomalies

Incident Response Guidance

If compromise is suspected:

Isolate affected systems immediately
Conduct full malware scans and forensic analysis
Reset all compromised credentials
Remove persistence mechanisms
Restore from secure backups

CIRT encourages to send reports of unusual behavior to: [email protected]

Check Also

270 Zimbra

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them …