logo

SideWinder Hacker Group Launches Fake Outlook and Zimbra Portals to Steal Login Credentials

ID: 01ba27ff-eb3c-5f33-8a3a-47aea8818d0e

STIX ID: report--01ba27ff-eb3c-5f33-8a3a-47aea8818d0e

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2025-10-03

Date Updated: 2026-04-13

Author: Priya

...
...

APT SideWinder’s "Operation SouthNet" deployed over 50 phishing domains between August and September 2025 using free hosting (Netlify, Pages.dev, workers.dev, b4a.run) to present fake Outlook and Zimbra login pages targeting government, military, maritime, aerospace and telecom organizations across Pakistan, Sri Lanka, Nepal, Bangladesh and Myanmar; the actor used direct POST exfiltration to technologysupport.help, Base64 session persistence, maritime-themed weaponized documents, hosted malware samples in open directories, and reused legacy C2 domains (e.g., govmm.org) — analysts recommend monitoring free hosting platforms, ingesting IoCs into SIEM/EDR, advanced filtering of login attempts, and regional CERT coordination.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.