SideWinder Hacker Group Targets Users with Fake Outlook/Zimbra Portals to Steal Login Credentials
The SideWinder APT group has escalated its credential harvesting operations in South Asia through advanced phishing campaigns. These operations target government, defense, and critical infrastructure organizations using fake webmail portals.
The SideWinder APT group has escalated its credential harvesting operations in South Asia through advanced phishing campaigns. These operations target government, defense, and critical infrastructure organizations using fake webmail portals.
This campaign marks a significant escalation from their activities in August 2024, which primarily involved 14 malicious webpages hosted on platforms such as Netlify and pages.dev.
The threat actors have maintained persistent phishing operations for over eight months, continuously adapting their strategies to avoid detection.
SideWinder's current campaign utilizes a multi-faceted approach to credential harvesting, focusing on fake Outlook Web App and Zimbra webmail login pages. The group has compromised infrastructure across various free hosting platforms, including Netlify, Cloudflare Pages, and Back4App, to host malicious portals.
In Bangladesh, the group targets the Directorate General of Defense Purchases (DGDP) with fake "secured file" portals imitating official defense procurement systems. These lures deceive officials into entering login credentials, believing they are accessing legitimate defense documents.
The SideWinder APT group has escalated its credential harvesting operations in South Asia through advanced phishing campaigns.
Nepal has been identified as a primary target, with 17 active phishing portals uncovered between May and September 2024. Approximately 70% of these operations mimic centralized government webmail systems, while the rest use politically-themed documents as bait.
In Myanmar, the Central Bank has been targeted through fake Zimbra portals, with stolen credentials directed to shared collection servers used in campaigns against other regional targets. This shared infrastructure demonstrates operational efficiency and resource optimization.
SideWinder also targets the maritime sector, maintaining open directories hosting malicious executables and decoy files. Command-and-control endpoints have been identified at themegaprovider.ddns.net and gwadarport.ddns.net, hosting over 40 distinct malware samples targeting Pakistan and Sri Lankan maritime operations.
The group's technical sophistication includes using hardcoded CSRF tokens for session tracking and multi-stage redirect mechanisms to obscure phishing flows. Spillover attacks have been identified against Singapore's Ministry of Manpower, indicating potential expansion of SideWinder's operational scope.
Security experts recommend proactive monitoring of free hosting platforms, enhanced email filtering, and regional cybersecurity cooperation to counter this persistent threat effectively.
Based on reporting by GBHackers.
