SideWinder APT Launches Cyberattacks on Indian Entities Posing as the Income Tax Department
## Cybersecurity: SideWinder APT Campaign Analysis
Cybersecurity: SideWinder APT Campaign Analysis
Zscaler Threat Hunting has detected an advanced espionage campaign targeting Indian entities through fraudulent portals impersonating the "Income Tax Department". This operation signifies a notable evolution in the SideWinder APT's tactics.
The threat actor, known as Rattlesnake or APT-C-17, employs DLL side-loading techniques using legitimate Microsoft binaries and mimics Chinese enterprise software protocols to evade detection systems.
The campaign exhibits precise targeting. Zscaler researchers observed geofencing behavior, where malware queries the victim's timezone using timeapi.io and worldtimeapi.org, proceeding only if a South Asian timezone (UTC+5:30) is detected, indicating a focus on India.
Enterprise victims include sectors such as Services, Retail, Telecommunications, and Healthcare across Asia Pacific, emphasizing strategic intelligence collection over opportunistic cybercrime.
The attack begins with phishing emails redirecting victims via URL shorteners to a fraudulent portal (gfmqvip.vip) mimicking India's Income Tax Department. Victims download "Inspection.zip," containing a legitimate Microsoft Defender executable (SenseCE.exe), a malicious MpGear.dll, and decoy certificates.
This operation signifies a notable evolution in the SideWinder APT's tactics.
This approach leverages trusted public cloud storage and URL shorteners to bypass reputation-based detection systems.
The attack involves Windows DLL hijacking. Executing "Inspection Document Review.exe" loads the malicious MpGear.dll. Zscaler's Zero Trust Exchange analyzes signals across SSL/TLS traffic, cloud activity, and web browsing to reveal complete attack chains.
After environment checks and sandbox evasion, the malware connects to 8.217.152.225 to retrieve a shellcode loader (/1bin). The final agent (mysetup.exe) is deployed to C:\install and configured via YTSysConfig.ini to communicate with 180.178.56.230.
This C2 protocol mimics Anqi Shen, a Chinese endpoint management tool, disguising malicious traffic as legitimate software communications.
The malicious code executes in memory, bypassing traditional file-scanning engines. SideWinder exploits visibility gaps in endpoint security, as EDR tools often miss browser redirections, archive downloads, and beaconing patterns.
This campaign highlights the evolving methodologies of state-sponsored actors, leveraging legitimate infrastructure and trusted binaries to evade defenses, underscoring the persistent threat of advanced persistent threats.
Based on reporting by GBHackers.
