SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials
ID: eedc5b0c-4ef1-56d8-9bf7-ea545071ec11
STIX ID: report--eedc5b0c-4ef1-56d8-9bf7-ea545071ec11
Feed Name: cybersecurityNews.com
A report attributes an active, highly targeted credential-harvesting campaign to APT SideWinder that has been running since at least February 2026 against South Asian government entities (including Bangladesh Navy and Pakistan’s Ministry of Foreign Affairs). The attackers used a phishing kit called Z2FA_LTS hosted on Cloudflare Workers which displays a fake Chrome PDF viewer and a pixel-perfect Zimbra webmail clone (reverse-proxying real assets) to trick users into submitting credentials; researchers identified multiple Worker subdomains, a developer opsec leak revealing the kit name and username, and recommended immediate credential rotation, reporting of malicious Worker domains, and monitoring for similar kits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
