logo

SideWinder’s Group New Upgrade Targets Ports & Maritime Facilities

ID: 43890227-097c-5d0d-836b-814646733024

STIX ID: report--43890227-097c-5d0d-836b-814646733024

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2024-07-29

Date Updated: 2026-04-13

Author: Kaaviya

...
...

SideWinder, a sophisticated nation-state-aligned APT, is running a focused campaign against ports and maritime organizations in the Indian Ocean and Mediterranean, initially targeting Pakistan, Egypt, and Sri Lanka and later expanding to Bangladesh, Myanmar, Nepal, and the Maldives. The actor uses social-engineered phishing with weaponized Office/RTF documents exploiting CVE-2017-0199 and CVE-2017-11882 to deploy multi-stage JavaScript-based malware, establish persistence and backdoors, and maintain C2 via DNS tunneling and Tor to facilitate lateral movement and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.