logo

SideWinder APT Caught Spying on India's Neighbor Gov'ts

ID: 0d2cef0a-8691-5069-b4a7-700722198b46

STIX ID: report--0d2cef0a-8691-5069-b4a7-700722198b46

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-05-22

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Acronis researchers attribute a targeted spear‑phishing campaign against government and military entities in South Asia to the SideWinder APT (aka Razor Tiger). The campaign registers numerous C2 domains and delivers malicious RTF attachments that leverage old but effective Microsoft Office vulnerabilities (CVE-2017-0199 and CVE-2017-11882) with contextual checks (geofencing, HTTP header validation) to selectively deploy a .NET modular espionage toolkit called StealerBot, aiming to steal credentials and sensitive information from entities across Sri Lanka, Bangladesh, Pakistan, and Nepal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.