Cyber Hacking News

‘Team Mysterious Bangladesh’ hackers target Indian education entity

0

A hacker group named “Team Mysterious Bangladesh” has claimed to have compromised the Indian Central Board of Higher Education (CBHE) systems.

CloudSEK’s contextual AI digital risk platform XVigil has discovered the attack. According to the advisory issued by the cybersecurity experts, the hackers would have stolen personally identifiable information (PII), including names, Aadhaar numbers, Indian Financial System Codes (IFSC codes) and other details of numerous individuals.

The group mentioned leaking information about students from 2004 to 2022 and they also shared a snapshot of the data for a student.

Access to the admin panel of the CBHE Delhi platform would allow any individual to see the results of all students from 2004 to 2022 and even delete or add records, CloudSEK explained.

So the hackers managed to get unauthorized access to the admin panel, enabling them to compromise the data for CBHE Delhi, India. Additionally, a directory of the domain was compromised by the hacktivist as they defaced it with their names.

CloudSEK said the leaked information could be used to gain initial access to the firm’s infrastructure, and commonly used or weak passwords could lead to brute-force attacks. With the data available, the threat actors could perform sophisticated ransomware attacks, exfiltrate data and maintain persistence.

Team Mysterious Bangladesh is known for using several scripts for distributed denial-of-service (DDoS) attacks and an HTTP flooding attack technique similar to DragonForce. Beyond the CBHE attack, the threat actor would have also conducted hacktivism-focused campaigns in Iran.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

French hospital suspends operations due to ransomware attack

Previous article

Antwerp’s city services went offline due to ransomware attack

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *