Tag: SideWinder APT

South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware
News

South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware

A threat actor called SideWinder has launched a new campaign targeting high-level government institutions in Bangladesh, Pakistan, and Sri Lanka. In order to guarantee that only victims in particular nations received the malicious content, the attackers employed spear phishing emails in conjunction with geofenced payloads, according to a report released to The Hacker News by Acronis researchers Santiago Pontiroli, Jozsef Gegeny, and Prakas Thevendaran. The attack chains use spear-phishing lures as a springboard to initiate the infection process and introduce StealerBot, a known piece of malware. It's important to note that the methodology aligns with recent SideWinder attacks that Kaspersky reported in March 2025. According to Acronis, the campaign's targets include the Ministry ...
SideWinder APT Strikes Middle East and Africa With Stealthy Multi-Stage Attack
News

SideWinder APT Strikes Middle East and Africa With Stealthy Multi-Stage Attack

Attacks on prominent targets and vital infrastructure in the Middle East and Africa have been launched by an advanced persistent threat (APT) actor suspected of having connections to India. The organization identified as SideWinder—also known as APT-C-17, Baby Elephant, Hardcore Nationalist, Leafperforator, Rattlesnake, Razor Tiger, and T-APT-04—has been linked to the activity. The group's use of malicious LNK files and scripts as infection vectors, public exploits, and public remote access tools (RATs) may give the impression that they are a low-skilled player, but a closer look at their operational details reveals their true skills. According to Kaspersky experts Vasily Berdnikov and Giampaolo Dedola read more about SideWinder APT Strikes Middle East and Africa With Stealthy Multi...