South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware
A threat actor called SideWinder has launched a new campaign targeting high-level government institutions in Bangladesh, Pakistan, and Sri Lanka.
In order to guarantee that only victims in particular nations received the malicious content, the attackers employed spear phishing emails in conjunction with geofenced payloads, according to a report released to The Hacker News by Acronis researchers Santiago Pontiroli, Jozsef Gegeny, and Prakas Thevendaran.
The attack chains use spear-phishing lures as a springboard to initiate the infection process and introduce StealerBot, a known piece of malware. It's important to note that the methodology aligns with recent SideWinder attacks that Kaspersky reported in March 2025.
According to Acronis, the campaign's targets include the Ministry ...

