Bahamut

Threat Actor updated 4 months ago (2024-05-04T17:07:35.333Z)
Download STIX
Preview STIX
Bahamut is a threat actor group known for its sophisticated cyber-espionage operations, targeting primarily South Asia. Meta's Adversarial Threat Report from the first quarter of 2023 identified Bahamut as one of three major groups involved in cyber espionage operations in the region, alongside Patchwork APT and a state-linked group in Pakistan. The company took action against these entities, removing approximately 110 accounts on Facebook and Instagram linked to Bahamut that were targeting individuals in Pakistan and India, including the Kashmir region. In addition, Bahamut has been known to use fake VPN apps for Android containing extensive spyware functionality, further highlighting their advanced tactics. In August 2023, new social engineering attacks by Bahamut were reported involving a fraudulent Android chat app called SafeChat. This application was used to facilitate a version of the CoverIm spyware aimed at exfiltrating mobile device data, according to BleepingComputer. The attack was attributed to Bahamut with a fair degree of confidence, although there were noted similarities in tactics to the advanced persistent threat group DoNot, believed to be linked to the Indian Government. These incidents underscore Bahamut's capacity for complex and targeted cyberattacks. Interestingly, while Bahamut's activities have mainly been traced back to South Asia, there are indications of links to China as well. A London-based operation creating fake personas impersonating US and EU companies and institutions, which later published negative commentary about Uyghur activists and critics of the Chinese state, was linked to individuals in China associated with Xi’an Tainwendian Network Technology. Despite the efforts of the actual operators to conceal their identities, this connection suggests that Bahamut may have a broader geographical reach and more diverse targets than initially assumed.
Description last updated: 2024-03-28T08:16:29.699Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Apt
Facebook
Meta
Spyware
Android
Vpn
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Bahamut Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
5 months ago
Saudi Arabia, UAE Top List of APT-Targeted Nations in the Middle East
CERT-EU
a year ago
Mobile spyware LetMeSpy ends operations following data breach
CERT-EU
a year ago
Threat Actor Bahamut Uses Fake Android Chat App To Steal Signal, WhatsApp Data
CERT-EU
a year ago
Higher VA tech, cyber compensation adopted
CERT-EU
a year ago
AVrecon botnet linked to SocksEscort proxy service
CERT-EU
a year ago
Fraudulent Android chat app leveraged in new Bahamut attack
CERT-EU
a year ago
Fake Android App Used to Exfiltrate Signal and WhatsApp User Data
CERT-EU
a year ago
New Android Malware Via WhatsApp steals Call logs, Locations, & Contacts
CERT-EU
a year ago
European Bank Customers Targeted in SpyNote Android Trojan Campaign
CERT-EU
a year ago
WhatsApp chats, personal information of users in India at risk, hackers using this app to target
CERT-EU
a year ago
Companies need to defend against the growing mobile threat
ESET
2 years ago
StrongPity espionage campaign targeting Android users | WeLiveSecurity
ESET
2 years ago
Bahamut cybermercenary group targets Android users with fake VPN apps | WeLiveSecurity
DARKReading
a year ago
Meta Expunges Multiple APT, Cybercrime Groups From Facebook, Instagram
CERT-EU
a year ago
Cyber security week in review: May 5, 2023
CERT-EU
a year ago
Сервисы Meta используются для шпионажа за пользователями из Южной Азии
CERT-EU
a year ago
Meta Cracks Down on South Asian Cyberespionage Groups
CERT-EU
a year ago
Meta: Social media leveraged in widespread cyberespionage operations
CERT-EU
a year ago
Five Driving Forces in the Tech Sector and the Future of Meta