RST TI Report Digest: 03 Nov 2025
ID: b46cb2f0-91c8-5642-b0d8-37fc44aa0f68
STIX ID: report--b46cb2f0-91c8-5642-b0d8-37fc44aa0f68
Feed Name: RST Cloud Blog
Threat Score
**SideWinder’s Shifting Sands — Click Once for Espionage:** Trellix ARC identified a sophisticated SideWinder APT campaign targeting diplomatic institutions in South Asia using spear‑phishing that delivered ClickOnce installers (ModuleInstaller and StealerBot); the adversary used geofencing, polymorphism, DLL sideloading and timing-based evasion to limit detection, and the report includes numerous IOCs (domains, URLs, file hashes, and email addresses) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
