Bignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails with disguised Agent Tesla attachments protected by Cassandra Protector. They compromised servers by installing Plesk and RoundCube, connected via SSH and RDP, and used advanced obfuscation methods to evade detection. Bignosa collaborated with another cybercriminal named Gods, who provided advice and assistance in their malicious activities. The actor has been linked to multiple phishing attacks and malware distribution campaigns, showcasing a high level of sophistication in their operations.
Executive Summary
Bignosa is a sophisticated threat actor targeting Australian and U.S. organizations through phishing campaigns utilizing Agent Tesla malware, protected by Cassandra Protector. They exploit server vulnerabilities by installing Plesk and RoundCube, leveraging SSH/RDP access, and employ advanced obfuscation techniques. Collaboration with a known cybercriminal, Gods, suggests potential ties to broader malicious networks.
Goals & Targeting
Bignosa's strategic objectives are likely financial gain or data theft, given the focus on enterprise targets and the use of credential-stealing malware such as Agent Tesla. The actor specifically targets Australian and U.S. organizations, which may be due to their access to critical infrastructure, financial systems, or sensitive data. Their operations suggest an interest in maintaining persistence within compromised networks, possibly for future exploitation or sale of stolen information. Typical victims include businesses and institutions with exposed servers or lax security protocols, particularly those using outdated software like Plesk or RoundCube.
Enhanced Description
Bignosa is a threat actor primarily targeting organizations in Australia and the United States through highly sophisticated phishing campaigns. Their operations involve distributing malware, particularly Agent Tesla, which is obfuscated using Cassandra Protector to evade detection. Once initial access is gained, the actor compromises servers by installing Plesk and RoundCube, frequently using SSH and RDP for remote access. The malware is then deployed to extract sensitive information, demonstrating a high level of technical expertise. Bignosa's collaboration with another cybercriminal, Gods, indicates a potential network of actors working in tandem to execute complex operations. This actor has been linked to multiple campaigns, highlighting a consistent pattern of using social engineering combined with server exploitation techniques. The use of advanced obfuscation and the deployment of known malicious tools suggest a goal of long-term access and data exfiltration.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Bignosa's campaigns typically involve spear-phishing emails with malicious attachments, followed by server exploitation through compromised credentials or unpatched software. The actor demonstrates operational tempo aligned with high-value targets, often leveraging well-known malware and obfuscation tools to avoid detection. Notable campaigns include compromising web servers via Plesk and RoundCube, using SSH/RDP for lateral movement, and exfiltrating data through covert channels. Their collaboration with Gods suggests potential ties to international cybercriminal ecosystems, expanding their operational reach and capabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the data is moderate, with high certainty regarding Bignosa's targeting of Australian and U.S. organizations, use of Agent Tesla and Cassandra Protector, and exploitation of Plesk/RoundCube. Gaps exist in confirming the actor's primary motivation, full attack chain details, and the exact relationship with Gods. Further intelligence on network infiltration patterns and long-term campaign objectives would improve confidence.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics