🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

~/ › Defacement › article

Defacement

Bangladeshi Hacktivist BNCT_1360 Attacks Bangladeshi Educational Institute For Fun?

> By Haider | Aug 26, 2026 | 7 min read


INCIDENT_MONITORING // ACADEMIC_SECTOR_EXPLOITATION
THREAT_CELL: BNCT_1360 (BLACK NIGHT CIVILIZATION TEAM)

In a striking display of opportunistic clout-chasing within South Asian cyber undergrounds, regional threat actors targeted a prominent Bangladeshi Educational Institute web server to celebrate a social media subscriber milestone. The collective, operating under the moniker BNCT_1360 (Black Night Civilization Team), claimed responsibility for defacing Patgati Government Junior High School (pgjhs.edu.bd) to commemorate reaching one thousand Telegram channel members.

Bangladeshi Educational Institute - Telegram milestone claim by BNCT_1360 for CyberAsia
Figure 1: Photographic evidence capturing BNCT_1360's Telegram broadcast claiming the compromise of pgjhs.edu.bd to celebrate reaching 1,000 members (invite links redacted by CyberAsia).

1. Incident Overview and Target Institutional Profile

The compromised domain belongs to Patgati Government Junior High School (PGJHS), a state-run academic establishment located in Gopalganj, Bangladesh. Serving hundreds of secondary students and administrative personnel, the institution maintains its primary digital portal on the national top-level academic domain (pgjhs.edu.bd).

On August 24, 2026, threat actors gained unauthorized access to the web server’s root file system, replacing the legitimate school homepage with an intrusive dark-mode defacement index. Claim broadcasts published on Telegram explicitly framed the attack as an celebratory demonstration: “Your website has been hacked to celebrate BNCT_1360 reaching 1K members.”

> TARGET_PROFILE // ACADEMIC_INFRASTRUCTURE
  • Victim Organization: Patgati Government Junior High School (PGJHS)
  • Target Domain: https://pgjhs.edu.bd/
  • Jurisdiction: Gopalganj District, Bangladesh (.edu.bd)
  • Attack Vector: Unauthorized Web File System Modification / Content Management Overwrite

2. Targeting the Bangladeshi Educational Institute Sector: Milestone Exploitations

The breach of a Bangladeshi Educational Institute exemplifies the phenomenon of “milestone hacking” prevalent among low to mid-tier threat syndicates. Rather than executing strategic espionage, extortion, or disruptive ransomware, these groups treat public-facing institutional web assets as vanity scoreboards to prove technical activity to their followers.

Bangladeshi Educational Institute - live defacement capture on pgjhs.edu.bd by BNCT_1360 for CyberAsia
Figure 2: Photographic evidence capturing the live web defacement of pgjhs.edu.bd displaying the Black Night Civilization Team (BNCT_1360) insignia and prayer tribute (CyberAsia intelligence visual).

Interestingly, while the primary motivation was declared as a subscriber celebration, the embedded defacement message featured a dual ideological tone. Below their official insignia, the threat actors injected a religious tribute honoring martyrs: “Your security is weak Peace and deep respect… honor to all those martyr brothers and sisters who sacrificed their lives… O Allah, grant them Jannatul Firdaus.” This pairing of casual clout-farming with solemn religious invocations is a recurring hallmark of decentralized South Asian hacktivist aesthetics.

> THREAT_ACTOR_DOSSIER // ATTRIBUTION_MATRIX
  • Threat Collective: BNCT_1360 (Black Night Civilization Team)
  • Affiliated Coalition: International Black Hat Hacker Group
  • Regional Theater: Bangladesh and South Asian Cyber Underground
  • Tactical Profile: CMS Exploitation, Web Defacements, Clout-Driven Social Broadcasting
Bangladeshi Educational Institute - March 3 Telegram disclaimer by BNCT_1360 for CyberAsia
Figure 3: Telegram intelligence telemetry from March 3 documenting BNCT_1360’s early compliance notice claiming the channel was strictly for gaming APKs and website demos (CyberAsia intelligence visual).

The Ideological Identity Crisis: From Gaming Disclaimers to Religious Defacements

A retrospective analysis of the collective’s historical channel telemetry reveals a confusing, highly contradictory ideological trajectory. In early channel records dating back to March 3, 2026, the channel administrator published an anxious, defensive notice directly addressed to the “Telegram Team and Channel Members.”

In the March 3 disclaimer, the operator insisted that the channel was established solely for "website and apk, gaming related content," explicitly denying any involvement in illegal activities or weapon distribution to evade administrative bans from Telegram moderators. Yet, months later, the nascent team executed a sharp pivot, rebranding as the Black Night Civilization Team, affiliating with the International Black Hat Hacker Group, and launching public web defacements against domestic educational infrastructure.

> THREAT_TELEMETRY // IDEOLOGICAL_DISSONANCE
  • March 3 Baseline: Timid disclaimers claiming non-malicious gaming APK modding to evade platform bans.
  • August 24 Transformation: Pivot to aggressive “Black Hat” persona, targeting educational portals for subscriber vanity milestones.
  • Muddled Operational Doctrine: An awkward juxtaposition of casual clout-chasing with solemn religious invocations, demonstrating the lack of a mature, cohesive strategic ideology.
Bangladeshi Educational Institute - BNCT_1360 channel biography and peaceful manifesto for CyberAsia
Figure 4: Telegram channel profile of BNCT_1360 recording 1,052 subscribers and claiming a peaceful advocacy mission despite executing offensive web defacements (CyberAsia intelligence visual).

The ‘Peaceful Advocacy’ Paradox: Rhetoric vs. Offensive Reality

Further illustrating the muddled doctrine of BNCT_1360 is the glaring paradox between the collective’s official channel biography and its real-world cyber activity. The group’s public profile, boasting 1,052 subscribers (confirming the achievement of their 1K milestone target), opens with traditional Islamic greetings and presents a pacifist mission statement:

“BNCT_1360 Team aims to raise awareness against discrimination, injustice, and oppression, unite people for positive purposes, and peacefully advocate for justice through digital platforms.”

The contradiction between claiming to peacefully advocate for justice while simultaneously joining the International Black Hat Hacker Group and compromising domestic secondary schools exemplifies the cognitive dissonance within immature hacktivist networks. The pursuit of social media notoriety and collective vanity frequently overtakes their stated ethical rhetoric, leading cells to target vulnerable academic servers simply to demonstrate technical dominance to their followers.

3. Regional Syndication and Underground Dynamics

As highlighted in CyberAsia’s investigation on Underground Hacktivist Alliances, groups like BNCT_1360 frequently operate within loose, multi-admin alliance networks. Collectives across Bangladesh, India, Pakistan, and Indonesia routinely cross-promote each other’s defacements, sharing attack mirrors across syndicated channels to inflate perceived operational influence.

Similar to recent opportunistic campaigns, including our analysis on how Indonesian threat actors breached Russian geological engineering portals, these collectives leverage automated vulnerability scanners to identify unpatched third-party plugins, outdated PHP frameworks, and default administrative credentials across underfunded public sector portals.

Cross-Border Campaigns: Retaliatory Operations Against Indian Infrastructure

Beyond casual milestone defacements targeting domestic academic portals, telemetry indicates that BNCT_1360 actively conducts cross-border cyber assaults targeting Indian infrastructure. Operating under the banner of regional resistance, the collective routinely deploys coordinated web application attacks, SQL injection exploits, and distributed denial-of-service (DDoS) barrages against Indian government, commercial, and educational web portals.

The group explicitly frames its persistent offensive against India as direct digital retaliation against Islamophobia, communal tensions, and perceived anti-Muslim discrimination across the subcontinent. This operational dynamic mirrors the broader regional cyber conflicts documented in CyberAsia’s briefing on XH4X CYB3R’s operations against India, where allied South Asian collectives collaborate under unified geopolitical hashtags to strike common national targets.

> OFFENSIVE_OPERATION // ANTI_ISLAMOPHOBIA_RETALIATION_AGAINST_INDIA
  • Targeted Cyberspace: Indian public sector websites, municipal servers, and educational institutions.
  • Stated Ideological Casus Belli: Retaliation against systemic Islamophobia, religious marginalization, and communal hostilities.
  • Coalition Mobilization: Synchronized operations coordinated alongside the International Black Hat Hacker Group to amplify DDoS traffic and defacement volume across Indian subdomains.

4. Technical Analysis: Web Application Weaknesses in Public Academic Portals

Educational portals in developing regions frequently suffer from severe resource constraints, resulting in unpatched web application frameworks and shared hosting vulnerabilities. In alignment with techniques cataloged in the MITRE ATT&CK Framework under Exploit Public-Facing Application (T1190), attackers typically exploit arbitrary file upload vulnerabilities to upload web shells, enabling full write access over the web root index.

5. Actionable Defense: Hardening Academic and Public Sector Web Assets

Mitigating opportunistic defacements across academic portals requires rigorous baseline hygiene and robust perimeter filtering.

For Academic Institutions and Web Administrators:

  • Disable Execution Permissions in Upload Directories. Configure web servers (Apache/Nginx) to explicitly prohibit the execution of script extensions (.php, .phtml, .sh) within user-accessible upload directories (/uploads, /media).
  • Implement Web Application Firewall (WAF) Protections. Follow CISA Cybersecurity Guidelines by deploying Cloudflare or ModSecurity rulesets to inspect incoming POST requests and block known web shell payloads and directory traversal vectors.
  • Enforce Continuous File Integrity Monitoring (FIM). Set up automated integrity watchdogs to instantly alert administrators and auto-revert unauthorized modifications to index files (index.php, index.html).
  • Maintain Secure Offline Backups and Credential Audits. Implement automated, offsite database and file backups. For confidential security incident reporting, submit via CyberAsia Secure Drop.

For Students, Faculty, and Public Observers:

  • Do Not Submit Credentials on Altered Pages. If an academic portal displays unauthorized banners or unexpected defacements, immediately refrain from entering student IDs or passwords.
  • Notify Institutional IT Support Promptly. Report visual alterations directly to school administrators via official alternate communication channels.

Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing Bangladeshi Hacktivist BNCT_1360 Attacks Bangladeshi Educational Institute For Fun? is part of the CyberAsia public archive. For organizations requiring real-time attack telemetry, check-host latency records, and edge firewall mitigation strategies for defacement incidents, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Haider

Lead Cyber Threat Intelligence (CTI) Editor at CyberAsia, specializing in regional cybercrime syndicates, threat actor tracking, and dark web intelligence investigations.

> related_intel --suggest