logo

From banks to battalions: SideWinder’s attacks on South Asia’s public sector

ID: 36c80dda-fb1f-553e-a810-29c245e3535f

STIX ID: report--36c80dda-fb1f-553e-a810-29c245e3535f

Feed Name: TRU Security by Acronis

Threat Score
85/100

Date Published: 2025-05-20

Date Updated: 2026-07-24

...
...

**Executive summary:** Acronis TRU uncovered an active SideWinder APT campaign targeting government and military organizations in Sri Lanka, Bangladesh and Pakistan using spear-phishing Word/RTF documents that exploit CVE-2017-0199 and CVE-2017-11882; the intrusion chain employs geofenced delivery, multistage shellcode-based loaders, server-side polymorphism, DLL sideloading and delivers StealerBot for credential theft and persistence, with numerous IOCs (file hashes, domains, URLs) and suggested mitigations included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.