logo

RST TI Report Digest: 03 Nov 2025

ID: b46cb2f0-91c8-5642-b0d8-37fc44aa0f68

STIX ID: report--b46cb2f0-91c8-5642-b0d8-37fc44aa0f68

Feed Name: RST Cloud Blog

Threat Score
85/100

Date Published: 2025-11-03

Date Updated: 2026-04-29

Author: RST Cloud

...
...

**SideWinder’s Shifting Sands — Click Once for Espionage:** Trellix ARC identified a sophisticated SideWinder APT campaign targeting diplomatic institutions in South Asia using spear‑phishing that delivered ClickOnce installers (ModuleInstaller and StealerBot); the adversary used geofencing, polymorphism, DLL sideloading and timing-based evasion to limit detection, and the report includes numerous IOCs (domains, URLs, file hashes, and email addresses) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.