Bahamut Apt

Threat Actor updated 5 months ago (2024-05-04T20:42:54.603Z)
Download STIX
Preview STIX
The Bahamut Advanced Persistent Threat (APT) group, a threat actor known for its malicious activities, is currently conducting an active campaign targeting Android users. This mobile campaign uses the same method of distributing Android spyware apps via websites that impersonate legitimate services, a technique previously observed with this group. The Bahamut APT primarily targets entities and individuals in the Middle East and South Asia, utilizing spearphishing messages and fake applications as their initial attack vector. ESET researchers have identified links to individuals in China associated with Xi’an Tainwendian Network Technology, an information technology company, despite attempts by the actual operators to conceal their identities. The group has been found creating fake personas mimicking companies and institutions in the U.S. and EU, initially posting content similar to the entity they're impersonating before switching to publishing negative commentary about Uyghur activists and critics of the Chinese state. In May 2023, Meta released its quarterly adversarial threat report highlighting three separate cyber-espionage campaigns linked to the Bahamut APT, the Patchwork APT, and an unnamed Pakistan-based threat actor. As part of their countermeasures, Meta was able to disrupt nearly 110 Facebook and Instagram accounts used by Bahamut APT in Android malware attacks against Indian and Pakistani government workers, military personnel, and activists. The report underscores the ongoing threat posed by Bahamut APT and the need for continued vigilance in cybersecurity practices.
Description last updated: 2024-05-04T17:46:46.706Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Android
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Bahamut Apt Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more