logo

SideWinder Espionage Campaign Expands Across Southeast Asia

ID: bda2ce97-f613-5e73-b8b5-af19252789b8

STIX ID: report--bda2ce97-f613-5e73-b8b5-af19252789b8

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Robert Lemos

...
...

Recent reporting attributes expanded cyber-espionage activity in Southeast Asia to the SideWinder (aka RagaSerpent) APT: operators use government-audit themed spear-phishing, credential theft, exploitation of long-patched MS Office flaws and DLL hijacking to stage payloads, while leveraging runtime-derived configuration and frequent C2/domain rotation to maintain long-term, hard-to-remediate access across government, telecommunications, maritime, logistics and nuclear sector targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.