Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Bignosa

Description

Bignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails with disguised Agent Tesla attachments protected by Cassandra Protector. They compromised servers by installing Plesk and RoundCube, connected via SSH and RDP, and used advanced obfuscation methods to evade detection. Bignosa collaborated with another cybercriminal named Gods, who provided advice and assistance in their malicious activities. The actor has been linked to multiple phishing attacks and malware distribution campaigns, showcasing a high level of sophistication in their operations.

AI Analysis

· 1 week ago

Executive Summary

Bignosa is a sophisticated threat actor targeting Australian and U.S. organizations through phishing campaigns utilizing Agent Tesla malware, protected by Cassandra Protector. They exploit server vulnerabilities by installing Plesk and RoundCube, leveraging SSH/RDP access, and employ advanced obfuscation techniques. Collaboration with a known cybercriminal, Gods, suggests potential ties to broader malicious networks.

Goals & Targeting

Bignosa's strategic objectives are likely financial gain or data theft, given the focus on enterprise targets and the use of credential-stealing malware such as Agent Tesla. The actor specifically targets Australian and U.S. organizations, which may be due to their access to critical infrastructure, financial systems, or sensitive data. Their operations suggest an interest in maintaining persistence within compromised networks, possibly for future exploitation or sale of stolen information. Typical victims include businesses and institutions with exposed servers or lax security protocols, particularly those using outdated software like Plesk or RoundCube.

Enhanced Description

Bignosa is a threat actor primarily targeting organizations in Australia and the United States through highly sophisticated phishing campaigns. Their operations involve distributing malware, particularly Agent Tesla, which is obfuscated using Cassandra Protector to evade detection. Once initial access is gained, the actor compromises servers by installing Plesk and RoundCube, frequently using SSH and RDP for remote access. The malware is then deployed to extract sensitive information, demonstrating a high level of technical expertise. Bignosa's collaboration with another cybercriminal, Gods, indicates a potential network of actors working in tandem to execute complex operations. This actor has been linked to multiple campaigns, highlighting a consistent pattern of using social engineering combined with server exploitation techniques. The use of advanced obfuscation and the deployment of known malicious tools suggest a goal of long-term access and data exfiltration.

Key Capabilities

  • Execution of spear-phishing campaigns with obfuscated Agent Tesla payloads
  • Deployment of Cassandra Protector for malware obfuscation
  • Server compromise via Plesk and RoundCube installation
  • Exploitation of remote access protocols (SSH, RDP)
  • Collaboration with external cybercriminals for operational support
  • Use of advanced obfuscation techniques to evade detection

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement
Data Exfiltration

ATT&CK Techniques

T1192 - Software Deployment
T1055 - Process Injection
T1078 - Valid Accounts
T1204.002 - User Execution - Malicious File
T1059.003 - Command-Line Interface
T1178 - Software Deployment Tool

Software / Tooling

Agent Tesla
Cassandra Protector
Plesk
RoundCube
SSH/RDP protocols

Campaigns & Victims

Bignosa's campaigns typically involve spear-phishing emails with malicious attachments, followed by server exploitation through compromised credentials or unpatched software. The actor demonstrates operational tempo aligned with high-value targets, often leveraging well-known malware and obfuscation tools to avoid detection. Notable campaigns include compromising web servers via Plesk and RoundCube, using SSH/RDP for lateral movement, and exfiltrating data through covert channels. Their collaboration with Gods suggests potential ties to international cybercriminal ecosystems, expanding their operational reach and capabilities.

IOC Patterns

  • Spear-phishing emails with macro-laced Office documents containing obfuscated Agent Tesla payloads
  • C2 communication patterns using domain generation algorithms (DGA)
  • Installation of Plesk and RoundCube on compromised servers
  • Use of SSH/RDP for remote access and lateral movement
  • Obfuscated malware samples protected by Cassandra Protector
  • Staging infrastructure on bulletproof hosting services

Recommended Actions

  • Implement advanced email filtering to detect obfuscated malicious attachments
  • Patch and secure Plesk and RoundCube installations to prevent exploitation
  • Deploy multi-factor authentication (MFA) for SSH/RDP access
  • Monitor for anomalous server activity, such as unexpected software installations
  • Conduct regular security training to mitigate spear-phishing risks
  • Deploy endpoint detection and response (EDR) tools to identify obfuscated malware

Suggested Tags

APT
cybercriminal
phishing
malware distribution
Australia-targeted
US-targeted

Confidence Assessment

The confidence level in the data is moderate, with high certainty regarding Bignosa's targeting of Australian and U.S. organizations, use of Agent Tesla and Cassandra Protector, and exploitation of Plesk/RoundCube. Gaps exist in confirming the actor's primary motivation, full attack chain details, and the exact relationship with Gods. Further intelligence on network infiltration patterns and long-term campaign objectives would improve confidence.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
APT
cybercriminal
phishing
malware distribution
Australia-targeted
US-targeted

Details

Type
Unknown
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.