A new APT organization that has been active since at least 2017 , mainly targeting cyber espionage activities in countries in South Asia . The attack method of this organization is similar to the SideWinder and Bitter organizations of Indian background , but there are essential differences in the details of the attack and the Trojans used. The organization is suspected to have an Indian background, and it mainly targets cyber espionage in government, military, diplomacy, intelligence, atomic energy and universities in South Asia, including Pakistan, Sri Lanka, Maldives and Bangladesh. In spear-phishing attacks, the organization made good use of information related to current political and military targets to produce phishing emails and bait documents, using SFX files disguised as PDF documents , and LNK files disguised as Trojan horse delivery vectors. CVE also used CVE in the early days -2017-11882 Vulnerability spread Trojan.
Exposure of sensitive information