SideWinder APT Hackers Attacking Indian Entities by Masquerading as the Income Tax Department of India
ID: e8d17b55-0044-57ed-8e1d-d1afc1d2ea3d
STIX ID: report--e8d17b55-0044-57ed-8e1d-d1afc1d2ea3d
Feed Name: cybersecurityNews.com
SideWinder APT is running a targeted phishing campaign against Indian users by impersonating the Income Tax Department; victims follow a short link to a fake tax portal which delivers Inspection.zip containing a signed Defender executable (renamed) and a malicious MpGear.dll. The DLL is used for side‑loading to execute attacker code, performs geofencing (South Asia timezone checks), sleeps to evade sandboxing, and stages a persistent backdoor (mysetup.exe) with C2 configuration and known IPs, enabling long‑term access and data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
