logo

SideWinder Targets Government Webmail With Bogus Chrome PDF Viewer and Zimbra Phishing Clone

ID: 942900b2-f86d-5eb2-b433-d597a0bbbd8e

STIX ID: report--942900b2-f86d-5eb2-b433-d597a0bbbd8e

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-04-21

Date Updated: 2026-05-05

Author: Varshini

...
...

SideWinder, an advanced persistent threat group, is running a targeted credential-harvesting phishing campaign against government and military targets in South Asia (notably the Bangladesh Navy and Pakistan’s Ministry of Foreign Affairs). The attackers use a Cloudflare Workers–hosted, pixel-perfect Zimbra webmail clone that dynamically proxies authentic assets and employs session/CSRF tricks and staged redirects to capture credentials; researchers discovered the campaign after a developer error exposed an application stack trace revealing internal identifiers useful for defender tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.