Tuesday , September 23 2025

South Asian APT to Compromise Phones of Military-linked Individuals In Bangladesh

A sophisticated South Asian APT group is conducting a widespread espionage campaign against military personnel and defense organizations in Sri Lanka, Bangladesh, Pakistan, and Turkey.

Threat actors are using a multi-stage attack strategy that combines phishing with new Android malware to target the mobile devices of military-related individuals.

Massive 22.2 Tbps DDoS Attack Sets New World Record

Cloudflare announced today that it has successfully defended against the largest recorded DDoS attack, which peaked at 22.2 terabits per...
Read More
Massive 22.2 Tbps DDoS Attack Sets New World Record

Microsoft to Build the “World’s Most Powerful AI Data Center”

Microsoft has announced a new $4 billion investment in Wisconsin for a second hyperscale AI data center. This adds to...
Read More
Microsoft to Build the “World’s Most Powerful AI Data Center”

Fraudsters swipe Tk 27 lakh from SCB cardholders

An organised racket has reportedly siphoned off lakhs from Standard Chartered Bangladesh's (SCB) credit card holders, raising serious cybersecurity concerns....
Read More
Fraudsters swipe Tk 27 lakh from SCB cardholders

EDR-Freeze: A Tool That Puts EDRs And Antivirus Into A Coma State

A new proof-of-concept tool named EDR-Freeze has been developed, capable of placing Endpoint Detection and Response (EDR) and antivirus solutions...
Read More
EDR-Freeze: A Tool That Puts EDRs And Antivirus Into A Coma State

First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Code

AI-driven malware called 'MalTerminal' utilizes OpenAI's GPT-4 to create harmful code like ransomware and reverse shells, indicating a major change...
Read More
First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Code

Gmail Data exposes via ChatGPT Deep Research Agent dubbed “ShadowLeak Zero-Click” Flaw

Cybersecurity researchers revealed a zero-click vulnerability in OpenAI ChatGPT's Deep Research agent that lets attackers leak sensitive Gmail inbox data...
Read More
Gmail Data exposes via ChatGPT Deep Research Agent dubbed “ShadowLeak Zero-Click” Flaw

Cyber attack disrupts several European airports: check-in and boarding systems affected

Several European airports are experiencing flight delays and cancellations due to a cyber attack on a check-in and boarding systems...
Read More
Cyber attack disrupts several European airports: check-in and boarding systems affected

Hacker claim to breach Link3; 189,000 Users data up for sale

A threat actor claims to have breached Link3, a major IT solutions and internet service provider based in Bangladesh. The...
Read More
Hacker claim to breach Link3; 189,000 Users data up for sale

Check Point Hosts “Securing the Hyperconnected World in the AI Era” in Dhaka

Check point, a cyber security solutions provider hosts an event titled "securing the hyperconnected world in the AI era" at...
Read More
Check Point Hosts “Securing the Hyperconnected World in the AI Era” in Dhaka

Microsoft Confirms 900+ XSS Vulns Found in IT Services

Cross-Site Scripting (XSS) is one of the oldest and most persistent vulnerabilities in modern applications. Despite being recognized for over...
Read More
Microsoft Confirms 900+ XSS Vulns Found in IT Services

The campaign shows strong operational security and advanced techniques, using legitimate cloud services and altered open-source tools to avoid detection.

Top level PDF phish and Decoy shown post cred theft (Source – StrikeReady)

Recent findings show ZIP files such as “Coordination of the Chief of Army Staff’s Visit to China.zip,” (MD5: cf9914eca9f8ae90ddd54875506459d6) which hold compressed PDFs meant to trick users.

These documeFraudulent domains are created to imitate legitimate organizations like the Bangladesh Army, DGDP, and Turkish defense companies, redirecting users who are misled by malicious links.

StrikeReady analysts identified that embedded JavaScript is used to hinder source code visibility, a tactic seen in various campaigns.

Documents are directing victims to phishing sites on compromised Netlify domains, such as mail-mod-gov-bd-account-conf-files.netlify.app and coordination-cas-visit.netlify.app, which look like real government and military email portals.

Researchers found over 50 malicious domains impersonating South Asian military and government organizations, such as the Bangladesh Air Force, DGDP, and Turkish defense firms like Roketsan and Aselsan.

Malware, distributed via APK files like Love_Chat.apk (MD5: 9a7510e780ef40d63ca5ab826b1e9dab), pretends to be real chat apps but creates a backdoor to access hacked devices.

The decompiled application shows it can extensively steal data, sending different document types to command-and-control servers.

Android RAT Infrastructure:

The attackers changed the original Rafel RAT code, removing credit information and creating their own command-and-control communications through domains like quickhelpsolve.com and kutcat-rat.com.

Decoys (Source – StrikeReady)

The malware requests dangerous permissions including ADD_DEVICE_ADMIN, READ_EXTERNAL_STORAGE, MANAGE_APP_ALL_FILES_ACCESS_PERMISSION, and READ_CONTACTS, enabling comprehensive device compromise.

The C2 infrastructure utilizes base64-encoded communication channels, with the primary command endpoint located at https://quickhelpsolve.com/public/commands.php.

This central control lets operators send commands to hacked devices, gather stolen data, and keep ongoing access to victim networks.

Security researchers found that hackers successfully breached military personnel in several countries, stealing SMS messages, contact lists with military ranks and duty stations, and sensitive documents.

BGD E-gov CIRT reported a coordinated phishing campaign has been uncovered targeting critical Bangladeshi infrastructure — particularly government organizations and law enforcement agencies. This attack leveraged compromised official email credentials to distribute fraudulent emails containing malicious attachments and deceptive login pages.

Bangladeshi gov.t/law enforcement email accounts compromised

Check Also

Villager

AI Pentesting Tool ‘Villager’ Merges Kali Linux with DeepSeek AI for Automated Attacks

The Villager framework, an AI-powered penetration testing tool, integrates Kali Linux tools with DeepSeek AI …