Advisories by BGD e-GOV CIRT

Post Image
SideWinder Spear-Phishing Campaign Against Bangladesh Leveraging Dual-Format Weaponized Documents
SideWinder, a persistent advanced persistent threat (APT) group with suspected India-nexus affiliations, is conducting an active spear-phishing campai....
30-Jul-2026 15:00:00
Read Details
Post Image
GoldFactory / GoldPickaxe - Biometric-Stealing Mobile Banking Trojan Targeting e-KYC & Digital Identity Systems
The current variant is distributed via a malicious domain spoofing KuaiBo, a prominent Chinese video-streaming and media-player application. Fake webs....
21-Jul-2026 11:00:00
Read Details
Post Image
Ghost Phishing: AES-GCM Encrypted Lures and EvilTokens Device-Code Phishing-as-a-Service Kit Targeting Microsoft 365 Accounts
The OAuth 2.0 Device Authorization Grant ("device code flow") is a legitimate authentication mechanism designed for devices with limited input capabil....
13-Jul-2026 15:15:00
Read Details
Post Image
AI-Branded Social Engineering, Phishing, and Malware Delivery Campaigns
The activity spans several delivery models, including phishing emails with urgent account or billing themes, adversary-in-the-middle token theft flows....
09-Jul-2026 11:00:00
Read Details
Post Image
FortiBleed Campaign Exposes FortiGate Devices in Bangladesh with Credential Compromise
The campaign targets FortiGate SSL-VPN and management interfaces to obtain sensitive information, including user credentials, session data, authentica....
07-Jul-2026 15:30:00
Read Details
Post Image
INC Ransomware Expands Cross-Platform Capabilities Targeting Enterprise and Mainframe Infrastructure Across the Asia-Pacific Region
The exposed attacker infrastructure contained ransomware payloads, Active Directory reconnaissance data, Group Policy deployment scripts, credential t....
05-Jul-2026 15:00:00
Read Details