The Bangladesh e-Government Computer Incident Response Team (BGD e-GOV CIRT) has raised concerns about a widespread malware campaign associated with the Nymaim loader, indicating a high number of potentially compromised systems throughout Bangladesh.
According to a recent report by the agency, over 27,000 instances of malware activity have been detected within the country, based on threat monitoring and telemetry data. These events reveal that infected devices are attempting to communicate with known botnet control servers.
Nymaim, also referred to as the Gozi ISFB loader, is a sophisticated malware framework historically utilized for distributing various malicious threats, including banking trojans, ransomware, and credential-stealing programs. Previously linked to the Avalanche botnet, a major cybercriminal network disrupted during the international Operation Avalanche, Nymaim continues to pose a threat with ongoing infections and related activities globally, including in Bangladesh.
CIRT has identified malicious behavior across at least 20 network providers, with infected systems trying to establish connections with recognized command servers, indicating persistent compromises in Bangladesh.
The malware operates in stages, enabling the download of additional malicious software post-infection. This flexibility allows attackers to modify the malware’s functionality over time, making detection more challenging. Nymaim is specifically crafted to pilfer sensitive data such as banking credentials, card information, and system data for fraudulent activities, account breaches, and identity theft.
Key sectors like banking, government, retail, and healthcare are commonly targeted by this malware, although ordinary users are also at risk of being impacted.
The typical propagation channels for this malware include malicious advertisements, infected email attachments, and compromised websites, with instances where users can get infected merely by visiting a malicious webpage. Once inside a system, the malware conceals itself by altering system configurations and placing files in standard directories, while employing evasion tactics to avoid detection by security tools.
CIRT has recommended organizations to enhance network monitoring, with a focus on identifying unusual outbound connections, suspicious domain activities, and unauthorized executable files. Additionally, they suggest blocking known malicious domains and IP addresses, deploying endpoint detection solutions, and regularly conducting forensic examinations of systems.
In scenarios where infection is suspected, organizations are advised to isolate affected devices, reset compromised credentials, and restore systems from secure backups. CIRT also encourages reporting any suspected incidents through official channels to contain potential threats effectively.
