logo

APT Sidewinder Abuses Netlify to Mimic Government and Military Portals in South Asia

ID: f9816d25-3e14-5630-ae69-20eee29f8c9d

STIX ID: report--f9816d25-3e14-5630-ae69-20eee29f8c9d

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

- Research using Hunt.io pivoting uncovered an automated, multilingual phishing framework operating across Chinese, English, and Japanese clusters that lures victims with bureaucratic/tax/HR-themed ZIP/RAR files and leverages shared scripts (download.php, visitor_log.php) and reusable infrastructure (multiple .vip/.xin/.sbs domains and Kaopu Cloud-hosted IPs); the report lists 28 webpages, multiple domains and IP IOCs, maps observed behavior to MITRE ATT&CK techniques, and provides mitigation guidance for blocking, detection, and user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.