logo

Operation SouthNet: SideWinder Targets South Asia Maritime

ID: 90a9e033-52c5-5921-9354-9d5ac1f93e2c

STIX ID: report--90a9e033-52c5-5921-9354-9d5ac1f93e2c

Feed Name: Hunt.io Blog

Threat Score
88/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

Operation SouthNet is a large-scale, Hunt.io-attributed SideWinder campaign targeting Pakistan, Sri Lanka, Nepal, Bangladesh, and Myanmar (with spillover to Singapore) that leverages free hosting platforms (Netlify, pages.dev, workers.dev, b4a.run) to deploy fake Outlook/Zimbra portals, maritime- and government-themed lure documents, and open directories staging malware. Analysts observed rapid domain churn (new phishing domains every 3–5 days), over 50 malicious domains, exposed malware samples and staging servers, multiple credential exfiltration servers (e.g., technologysupport.help, drive-nepal-gov.com, myanmar-org-mail.com), infrastructure overlap with legacy SideWinder C2s, and a comprehensive set of defanged IOCs and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.