Thu, 23 Oct 2025

Hacker Group ‘Mysterious Elephant’ Targets Bangladesh and Neighbouring Nations

Khaborwala Online Desk

Published: 20 Oct 2025, 06:04 pm

Photo: Collected

A newly identified hacker group known as ‘Mysterious Elephant’ has been actively operating across the Asia-Pacific region since the beginning of this year, according to Kaspersky’s Global Research and Analysis Team (GReAT).

Kaspersky reports that the group primarily targets government agencies and foreign affairs-related organisations, aiming to steal sensitive and classified information, including official documents, images, and archived files. Among its confirmed targets are Bangladesh, Pakistan, Afghanistan, Nepal, Sri Lanka, and several neighbouring countries.

Scope and Intent of Attacks

AspectDetails
Primary TargetsGovernment and diplomatic institutions
Targeted RegionsBangladesh, Pakistan, Afghanistan, Nepal, Sri Lanka, others
ObjectivesTheft of sensitive data (documents, archives, photos)
Additional FocusAttempts to steal WhatsApp information and user data

 

Kaspersky has further revealed that the attackers are attempting to exfiltrate WhatsApp files, shared media, and documents, reflecting an expansion of their data-harvesting efforts beyond traditional systems.

 

In its 2025 cyber campaign, Mysterious Elephant has significantly refined and diversified its attack methods. The group now uses a combination of custom-built malware and open-source tools for conducting targeted cyber intrusions.

Their operations rely heavily on PowerShell scripts to execute commands, deploy malware, and maintain persistent access through legitimate software — a tactic designed to evade detection.

Key Malware Tools Used by Mysterious ElephantFunctions
BabshellActs as a reverse shell enabling direct system access and data exfiltration.
MemloaderLoads malicious code into memory, avoiding file-based detection.
HiddenDeskConceals malware activity in system memory to bypass security software.

 

These tools allow the hackers to perform covert operations, ensuring their presence remains undetected by most standard antivirus defences.

 

According to Noushin Shabbab, Principal Security Researcher at Kaspersky GReAT, the group has built a highly resilient and discreet operational infrastructure.

“Mysterious Elephant’s framework is designed to remain hidden and resist takedown efforts. They employ multiple domains, wildcard DNS records, VPS services, and cloud hosting to diversify and obscure their network,” said Shabbab.

A particularly concerning tactic is the use of wildcard DNS records, which enables the automatic generation of new subdomains for every connection request — making tracking and blocking their operations exceedingly difficult for cybersecurity teams.

 

Kaspersky has urged users and institutions to strengthen their cybersecurity measures to combat such advanced threats. The company recommends the adoption of its enhanced security solutions, including:

Recommended Kaspersky SolutionsPurpose
Kaspersky NextComprehensive cybersecurity platform for enterprises
Compromise AssessmentIdentifies ongoing or past breaches within networks
Managed Detection and Response (MDR)Real-time threat monitoring and defence
Incident ResponseImmediate containment and investigation of cyber incidents
Threat IntelligenceProvides up-to-date insights on evolving global threats

 

The discovery of Mysterious Elephant highlights a growing trend of state-level or state-sponsored cyber espionage in South Asia, with Bangladesh emerging as one of the primary targets in this sophisticated regional campaign.

Rashedur Rahman Crowned Champion at DRU Chess Tournament

Dhaka, Wednesday — Rashedur Rahman of Bangladesh Pratidin has emerged as the champion in the chess c...

Bangladesh Eyes the Final in the Multi-Million Taka Volleyball Tournament

Volleyball, once a widely popular sport during the 1970s and 1980s in Bangladesh, had gradually fade...

Four More Die of Dengue in Bangladesh as 942 New Patients Admitted in 24 Hours

Bangladesh continues to grapple with a severe dengue outbreak as four more people have died and 942...

Major Surge in Market Indices, Yet Trading Volume Hits Four-Month Low

Despite a significant rise in market indices, trading activity on the country’s stock exchanges fell...

FIFA Trains 32 Bangladeshi Coaches to Strengthen Football Talent Identification

In an effort to ensure that no potential football talent in Bangladesh goes unnoticed or unfairly ov...

Pharmaceutical Raw Materials Worth Tk 2 Billion Destroyed

Pharmaceutical raw materials valued at at least Tk 2 billion have been destroyed in a fire at the ca...

Gold Price Hits Record High, Rises by Tk 1,050 Per Bhori

The Bangladesh Jewellers Association (BAJUS) has raised the price of 22-carat gold by Tk 1,050 per b...

Bangladesh Back in the Field, Nahida and Marufa Return for ‘Do or Die’ World Cup Clash

Bangladesh’s women’s cricket team will face Sri Lanka in their sixth league match of the Women’s One...

BSRM Limited to Distribute Tk 149 Crore Dividend; BSRM Steels to Pay Tk 188 Crore

Two listed companies of the BSRM Group, Bangladesh Steel Re-Rolling Mills (BSRM) Limited and BSRM St...

Remittance Inflow Records 13.6% Growth up to 18 October

Bangladesh’s remittance earnings have witnessed a 13.6 percent year-on-year increase, reaching US$9....

“I Spoke About Divorce in Anger”: Mahia Mahi Clarifies Her Marital Status

Bangladeshi actress Mahia Mahi has clarified that she is not divorced from her politician husband Ra...

Remote-Controlled Firefighting Robot Deployed to Combat Blaze at Dhaka Airport

A remote-controlled firefighting robot has been deployed at Hazrat Shahjalal International Airport i...