From banks to battalions: SideWinder’s attacks on South Asia’s public sector
ID: 36c80dda-fb1f-553e-a810-29c245e3535f
STIX ID: report--36c80dda-fb1f-553e-a810-29c245e3535f
Feed Name: TRU Security by Acronis
**Executive summary:** Acronis TRU uncovered an active SideWinder APT campaign targeting government and military organizations in Sri Lanka, Bangladesh and Pakistan using spear-phishing Word/RTF documents that exploit CVE-2017-0199 and CVE-2017-11882; the intrusion chain employs geofenced delivery, multistage shellcode-based loaders, server-side polymorphism, DLL sideloading and delivers StealerBot for credential theft and persistence, with numerous IOCs (file hashes, domains, URLs) and suggested mitigations included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
