**Summary of the Cyberattack on Bangladesh Military by DoNot APT**:
A live cyber-espionage operation by the DoNot APT group (APT-C-35), suspected to be India-aligned, targets the Bangladesh military using spear-phishing techniques.
**Key Points**:
- **Attack Type**: Targeted spear-phishing through an RTF file masquerading as a senior officer's biography.
- **Infection Method**: Utilized remote template injection to fetch malicious macros that led to multi-stage payload delivery through disguised file types.
- **C2 Infrastructure**: Command servers were operational during the investigation, delivering second-stage modules to real victims.
- **Impact**: Ongoing campaign with focused intelligence collecting on Bangladeshi defense staff since at least 2016.
- **Detection Recommendations**: Monitor outbound HTTPS traffic for specific parameters, check for spoofed OneDrive tasks, and treat suspicious RTF files cautiously.