In September 2025, a threat actor identified as SideWinder launched a fresh assault against a European embassy in the Indian capital of fresh Delhi, as well as several organizations in Bangladesh, Pakistan, and Sri Lanka.
In a report released last week, Trellix researchers Ernesto Fernández Provecho and Pham Duy Phuc noted that the activity shows a significant evolution in SideWinder’s TTPs, specifically the adoption of a novel PDF and ClickOnce-based infection chain in addition to their previously known Microsoft Word exploit vectors.
From March to September 2025, four waves of spear-phishing emails were sent. The attacks’ goal was to collect sensitive data from vulnerable hosts by dropping malware families including ModuleInstaller and StealerBot.
StealerBot is a.NET implant that can launch a reverse shell, deliver more malware, and gather a variety of data from compromised hosts read more about SideWinder Adopts New ClickOnce-Based Attack Chain Targeting South Asian Diplomats.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
