SideWinder Utilizes New Infrastructure to Target Ports and Maritime Facilities in the Mediterranean Sea
ID: aa153eae-325d-5c68-b5f4-968630675f4e
STIX ID: report--aa153eae-325d-5c68-b5f4-968630675f4e
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs reports an active SideWinder APT campaign targeting maritime ports and related organizations across Pakistan, Egypt, Sri Lanka and neighboring countries using carefully crafted visual-bait documents that leverage outdated Office/RTF vulnerabilities (CVE-2017-0199, CVE-2017-11882) to stage multi-step JavaScript payload delivery; the report includes technical analysis, IoCs (file hashes, malicious domains, IPs), MITRE ATT&CK mapping, YARA rules and mitigation recommendations focused on patching, phishing awareness and advanced detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
