Wednesday , September 23 2026
Nymaim

BD CIRT detected over 27,000 Nymaim/Avalanche Malware related events in BD

There has been a sharp rise in malware linked to the Nymaim / Avalanche loader in Bangladesh. CIRT BD observed over 27,000 malware events, which means bad actors are trying to infect systems and there is ongoing contact with the botnet.

Figure: Detected Nymaim / Avalanche- Nymaim Malware Communications from Bangladesh IP Addresses, BD CIRT

Threat Overview

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Nymaim (also known as Gozi ISFB Loader) is a multi-stage malware loader used to deploy additional malicious payloads, including:

Banking trojans
Credential stealers
Ransomware
Remote access tools (RATs)

The malware is highly adaptive, allowing attackers to update capabilities post-infection through command-and-control (C2) servers.

Key Findings in Bangladesh

27,000+ malware events detected
Activity across 20+ network providers (ASNs)
Multiple compromised hosts communicating with botnet servers
C2 communication captured via sinkhole monitoring

These signs show that there are infected devices in Bangladesh networks that are trying to reconnect with known harmful servers.

Targeted Data

Nymaim infections aim to steal sensitive information such as:

Banking credentials
Payment card data
System configuration details

This data is commonly used for

Financial fraud
Account takeovers
Identity theft
Secondary cyberattacks

Malware File Names Observed

Suspicious File Names:
update.exe
flashplayer_update.exe
svchost.exe
java_update.exe

Malicious Domains (examples):

g-update[.]net
secure-update[.]biz
update-service[.]org

Known Malicious IPs:
184.105.192[.]2
185.82.202[.]132
91.220.131[.]37

Behavioral Indicators:

Outbound HTTP/HTTPS traffic to unknown domains
Encrypted payload downloads
Activity in AppData/Temp directories

Organizations in Bangladesh are strongly advised to:

Block known malicious IPs and domains
Implement DNS sinkholing
Deploy Endpoint Detection & Response (EDR)
Monitor unusual DNS and HTTP traffic
Sandbox suspicious files and attachments
Continuously monitor networks for anomalies

Incident Response Guidance

If compromise is suspected:

Isolate affected systems immediately
Conduct full malware scans and forensic analysis
Reset all compromised credentials
Remove persistence mechanisms
Restore from secure backups

CIRT encourages to send reports of unusual behavior to: [email protected]

Check Also

Secure Email Gateway

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known …