HAZY_TIGER__2022__Cisco_Talos_Intelligence_Group_-_Comprehensive_Threat_Intelligence_Bitter_APT_adds_Bangladesh_to_their_targets.pdf
ID: 1970b774-8b64-44ef-a14e-1a303a2cbcb7
STIX ID: report--1970b774-8b64-44ef-a14e-1a303a2cbcb7
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2022-05-19
Last Modified Date: 2022-05-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos describes an ongoing Bitter APT campaign (since Aug 2021) targeting Bangladeshi government personnel via spear-phishing attachments (weaponized RTF/Excel) that exploit known Microsoft Office vulnerabilities to install a downloader trojan named "ZxxZ" which provides remote file execution and fetches additional payloads; the report includes infrastructure, IOCs (domains, URLs, SSL thumbprints), detailed malware analysis, exploitation chains, and mitigation recommendations.
