HomeSecuritySideWinder hackers target government institutions in Asia

SideWinder hackers target government institutions in Asia

Government institutions in Asia, specifically in Sri Lanka, Bangladesh, and Pakistan, are the latest targets of a coordinated cyber espionage campaign orchestrated by the notorious SideWinder.

SideWinder hackers government institutions in Asia

According to a new report from Acronis, the group uses phishing emails combined with geofenced payloads — a technique that ensures that only users in selected target countries receive the malicious content.

The attack relies on spear-phishing as the initial means of penetration, with the ultimate goal of installing “StealerBot,” a malware designed to steal data and maintain persistent access to the victim’s network. The campaign’s modus operandi aligns with recent SideWinder operations that Kaspersky also documented earlier this year.

See also: RVTools site hacked and distributed Bumblebee malware

Among the confirmed targets are sensitive government entities, such as:

  • the Telecommunications Regulatory Authority, the Ministry of Defense and the Ministry of Finance of Bangladesh
  • the Directorate of Domestic Technical Development of Pakistan
  • the Department of External Resources, the Treasury Operations Department, the Ministry of Defense and the Central Bank of Sri Lanka

In these attacks, hackers exploit known vulnerabilities in Microsoft Office (CVE-2017-0199 and CVE-2017-11882) to remotely execute malicious code and maintain their presence on government networks.

See also: Ransomware gangs use Skitnet malware

According to Acronis' analysis, the malicious documents used in the attacks trigger the CVE-2017-0199 vulnerability, allowing the download of secondary payloads that install the StealerBot malware . The installation is done via DLL side-loading, increasing the difficulty of detecting the infection.

A notable feature of the campaign is the use of geographically targeted payloads (as we mentioned above). If the recipient of the phishing email does not meet the geographic targeting criteria, the system sends a harmless RTF document as a decoy.

The primary malicious file, an RTF file, exploits the CVE-2017-11882 vulnerability in the Equation Editor of Microsoft Office to launch a shell-based loader, which in turn activates StealerBot.

SideWinder hackers target government institutions in Asia
SideWinder hackers target government institutions in Asia

StealerBot, according to Kaspersky, is a .NET implant with the ability to install additional malware, create a reverse shell , and collect sensitive data from the victim. This includes screenshots, keystrokes, saved passwords, and files.

See also: Phishing emails distribute Horabot malware in Latin America

Researchers note that the SideWinder group demonstrates remarkable consistency and organizational continuity, without long periods of inactivity. The group, known for targeted espionage on government organizations, now leverages advanced techniques and “smart” malicious payloads to ensure that attacks only hit selected targets.

This campaign underscores the need for continuous vigilance by governmental and strategic entities, especially in areas of high geopolitical interest.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS