Operation SouthNet: SideWinder Targets South Asia Maritime
ID: 90a9e033-52c5-5921-9354-9d5ac1f93e2c
STIX ID: report--90a9e033-52c5-5921-9354-9d5ac1f93e2c
Feed Name: Hunt.io Blog
Operation SouthNet is a large-scale, Hunt.io-attributed SideWinder campaign targeting Pakistan, Sri Lanka, Nepal, Bangladesh, and Myanmar (with spillover to Singapore) that leverages free hosting platforms (Netlify, pages.dev, workers.dev, b4a.run) to deploy fake Outlook/Zimbra portals, maritime- and government-themed lure documents, and open directories staging malware. Analysts observed rapid domain churn (new phishing domains every 3–5 days), over 50 malicious domains, exposed malware samples and staging servers, multiple credential exfiltration servers (e.g., technologysupport.help, drive-nepal-gov.com, myanmar-org-mail.com), infrastructure overlap with legacy SideWinder C2s, and a comprehensive set of defanged IOCs and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
