logo

SideWinder APT Launches Operation SouthNet, Weaponizing Netlify and Pages.dev for Espionage

ID: 0df1c5f2-820a-5c5a-b35b-11fa5b99dc18

STIX ID: report--0df1c5f2-820a-5c5a-b35b-11fa5b99dc18

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

Hunt Intelligence documents Operation SouthNet, an active SideWinder campaign using 50+ malicious domains on free hosting platforms to deploy fake Outlook/Zimbra portals and phishing kits that harvest credentials from government, defense, telecom and maritime targets across Pakistan, Sri Lanka, Nepal, Bangladesh and Myanmar, with evidence of infrastructure recycling, C2 reuse, and maritime-focused lure documents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.