SideWinder Hacker Group Launches Fake Outlook and Zimbra Portals to Steal Login Credentials
ID: 01ba27ff-eb3c-5f33-8a3a-47aea8818d0e
STIX ID: report--01ba27ff-eb3c-5f33-8a3a-47aea8818d0e
Feed Name: Cyber Press
APT SideWinder’s "Operation SouthNet" deployed over 50 phishing domains between August and September 2025 using free hosting (Netlify, Pages.dev, workers.dev, b4a.run) to present fake Outlook and Zimbra login pages targeting government, military, maritime, aerospace and telecom organizations across Pakistan, Sri Lanka, Nepal, Bangladesh and Myanmar; the actor used direct POST exfiltration to technologysupport.help, Base64 session persistence, maritime-themed weaponized documents, hosted malware samples in open directories, and reused legacy C2 domains (e.g., govmm.org) — analysts recommend monitoring free hosting platforms, ingesting IoCs into SIEM/EDR, advanced filtering of login attempts, and regional CERT coordination.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
