Tuesday , September 15 2026
holidays

ALERT
BGD CIRT warn of Botnet, APT, RAT and Malware attack during holidays

Bangladesh is preparing for a nationwide Eid holiday; on the contrary a different kind of “celebration” is occurring in the dark corners of the web. While most professionals are logging off for a well-deserved break, automated scripts are just getting started, scanning for “digital silence.”

According to cyber security alert issued by BGD e-GOV CIRT on 15 March 2026, the long holiday creates a “perfect storm” for IT and cyber security departments: a combination of unattended systems, reduced operational staffing, and a significant lag in incident response times.

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

The “Greeting Card” Trap (Phishing Evolution)

One of the most insidious methods utilized by threat actors is the weaponization of cultural norms. During festive seasons, our collective psychological guard drops. We expect outreach from friends, family, and colleagues, which creates an opening for “Initial Access Brokers” to exploit.

Cybercriminals disguise credential harvesting attempts as routine holiday communications, banking on the fact that an exhausted employee checking their phone between festivities is less likely to inspect a URL.

“Attackers may distribute phishing emails disguised as: Holiday greetings, Financial notifications, Government announcements, HR or payroll updates.”

This isn’t just about a stolen password; it is the first link in a chain designed to transform a simple celebratory message into a gateway for total network compromise.

The Sophisticated “Chain Reaction” of Ransomware

Modern cyberattacks are rarely spontaneous events; they are calculated, multi-stage operations. Intelligence indicates that sophisticated groups deploy malware to establish a “Persistent Foothold” long before the final payload is delivered.

CIRT said, the typical attack chain follows a lethal progression: Phishing Email → Malware Loader → Remote Access → Lateral Movement → Ransomware Deployment.

The stage of Lateral Movement is where the real damage occurs. This is the phase where an attacker moves beyond a single compromised workstation to find the “crown jewels”—the banking databases, government records, or sensitive CII files. By the time the ransomware is finally activated and files are encrypted, the intruder may have been living in the network for weeks, mapping out your vulnerabilities while the office was empty.

IoT and Mobile Devices are the New Front Line

The 15 March alert highlights a massive “Botnet Ecosystem” including notorious families such as Mirai, MikroTik, Avalanche Network, and Hajime. However, a critical development in this landscape is the rise of Android Malware and Mobile Botnets, specifically Android BadBox, Android Void, and Android Hummer.

There is a biting irony here: the very devices that power our connected lives—our smartphones and office routers—are being turned into weapons against our national digital infrastructure. These botnets are used to orchestrate Distributed Denial-of-Service (DDoS) attacks targeting:

• Online banking systems and payment gateways
• Government portals and telecom service

The Invisibility of APT Clusters

Beyond the typical opportunistic hacker, Bangladesh’s digital ecosystem is being actively monitored by Advanced Persistent Threat (APT) clusters including Lazarus, MuddyWater, SideWinder, Transparent Tribe, Patchwork, Bitter APT, and the Donot Team.

These are not amateur operations; these are entities with high-level “multi-stage attack capability.” They specifically target Critical Information Infrastructure (CII), scanning for unpatched internet-facing services such as VPN gateways, web servers, and misconfigured cloud infrastructure. They strike when they know human oversight is at its lowest, ensuring their infiltration remains invisible for as long as possible.

The “Zero-Downtime” Defense Strategy

To counter these threats organizations must adopt a zero-downtime mentality toward defense, moving from reactive patching to proactive Attack Surface Management. The following measures are strategic necessities:

• 24/7 Proactive Monitoring: Maintain round-the-clock surveillance through a Security Operations Center (SOC) using SIEM, WAF, and endpoint protection to detect anomalies in real-time.
• Hardened Access Controls: Mandate Multi-Factor Authentication (MFA) for all remote access and secure every VPN gateway.
• Aggressive Lifecycle Management: Ensure all systems are patched and, more importantly, phase out unsupported or end-of-life (EOL) software that can no longer be defended.
• Data Resilience and Redundancy: Maintain secure, offline backups and test your restoration procedures. A backup is only as good as your last successful test.
• Account Hygiene: Review and disable dormant or inactive accounts and temporarily restrict non-essential system access for the duration of the holiday.

A Security Mindset for the Future

The alert issued on 15 March 2026 is a stark reminder that digital convenience requires constant, proactive vigilance. CIRT recommended If any organization identifies any Indicators of Compromise (IOCs) or suspicious activity, report it immediately to the BGD e-GOV CIRT at: [email protected] or [email protected]

 

Check Also

ShinyHunters

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center …