Tuesday, February 11, 2025
HomeCyber AttackBitter APT Hackers Uses Non-existent Email Account/Domain To Send Weaponized Emails

Bitter APT Hackers Uses Non-existent Email Account/Domain To Send Weaponized Emails

Published on

SIEM as a Service

Follow Us on Google News

The government of Bangladesh has been targeted more than once by Bitter, an APT group that focuses on cyberespionage. It has developed a new malware that enables it to download and execute remote files.

A typical example of Bitter’s targeting scope, which has not changed since 2013, is the campaign, which has been ongoing since August 2021. The threat analysts at Cisco Talos discovered the campaign and provided details on how it was executed.

Citing IP address overlap, encryption commonality, and module name scheme, Cisco Talos researchers attribute this campaign in part to Bitter.

Malicious Infection Chain

Cisco detected two infection chains and both started with spear-phishing emails, during this campaign targeting various government organizations in Bangladesh. Here, to make the messages appear as if they came from a government organization in Pakistan, they have been sent via spoofed email addresses.

In this case, an attacker likely exploited a vulnerability in the Zimbra mail server, which enabled attackers to send emails from an illegitimate address.

One of the main differences between the two infection chains is the type of attachment included in the malicious email and here they are:- 

  • One has an .RTF document.
  • The other one has an .XLSX document.

These RTF documents can be exploited to trigger remote code execution by exploiting CVE-2017-11882 and getting access to machines using vulnerable versions of Microsoft Office and run arbitrary code.

An exploit for two CVEs, CVE-2018-0798 and CVE-2018-0802, are triggered by opening the Excel spreadsheet. On outdated versions of Microsoft Office, remote code execution (RCE) is the result.

A scheduled task that is created by the exploit is in charge of downloading the payload for this particular attack. This task succeeds in connecting to the host server and downloading the trojan every five minutes after the initial infection.

ZxxZ Trojan

The executable file zxxZ is a 32-bit version of Visual C++ compiled as a 32-bit version of the malware that sends data back to the C2 server with a separator used only by the malware.

The experts at Cisco Talos stated:-

“The trojan masquerades as a Windows Security update service and allows the malicious actor to perform remote code execution, opening the door to other activities by installing other tools.”

Moreover, a number of anti-detection features are employed by the malware, such as obfuscated strings, as well as the ability to look for and kill Kaspersky and Windows Defender processes.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

SHA256 Hash Calculation from Data Chunks

The SHA256 algorithm, a cryptographic hash function, is widely used for securing data integrity...

New Report of of 1M+ Malware Samples Show Application Layer Abused for Stealthy C2

A recent analysis of over one million malware samples by Picus Security has revealed...

Seven-Year-Old Linux Kernel Bug Opens Door to Remote Code Execution

Researchers have uncovered a critical vulnerability in the Linux kernel, dating back seven years,...

Ransomware Payments Plunge 35% as More Victims Refuse to Pay

In a significant shift within the ransomware landscape, global ransom payments plummeted by 35%...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

SHA256 Hash Calculation from Data Chunks

The SHA256 algorithm, a cryptographic hash function, is widely used for securing data integrity...

New Report of of 1M+ Malware Samples Show Application Layer Abused for Stealthy C2

A recent analysis of over one million malware samples by Picus Security has revealed...

Seven-Year-Old Linux Kernel Bug Opens Door to Remote Code Execution

Researchers have uncovered a critical vulnerability in the Linux kernel, dating back seven years,...