Government institutions in Asia, specifically in Sri Lanka, Bangladesh, and Pakistan, are the latest targets of a coordinated cyber espionage campaign orchestrated by the notorious SideWinder.

According to a new report from Acronis, the group uses phishing emails combined with geofenced payloads — a technique that ensures that only users in selected target countries receive the malicious content.
The attack relies on spear-phishing as the initial means of penetration, with the ultimate goal of installing “StealerBot,” a malware designed to steal data and maintain persistent access to the victim’s network. The campaign’s modus operandi aligns with recent SideWinder operations that Kaspersky also documented earlier this year.
See also: RVTools site hacked and distributed Bumblebee malware
Among the confirmed targets are sensitive government entities, such as:
- the Telecommunications Regulatory Authority, the Ministry of Defense and the Ministry of Finance of Bangladesh
- the Directorate of Domestic Technical Development of Pakistan
- the Department of External Resources, the Treasury Operations Department, the Ministry of Defense and the Central Bank of Sri Lanka
In these attacks, hackers exploit known vulnerabilities in Microsoft Office (CVE-2017-0199 and CVE-2017-11882) to remotely execute malicious code and maintain their presence on government networks.
See also: Ransomware gangs use Skitnet malware
According to Acronis' analysis, the malicious documents used in the attacks trigger the CVE-2017-0199 vulnerability, allowing the download of secondary payloads that install the StealerBot malware . The installation is done via DLL side-loading, increasing the difficulty of detecting the infection.
A notable feature of the campaign is the use of geographically targeted payloads (as we mentioned above). If the recipient of the phishing email does not meet the geographic targeting criteria, the system sends a harmless RTF document as a decoy.
The primary malicious file, an RTF file, exploits the CVE-2017-11882 vulnerability in the Equation Editor of Microsoft Office to launch a shell-based loader, which in turn activates StealerBot.

StealerBot, according to Kaspersky, is a .NET implant with the ability to install additional malware, create a reverse shell , and collect sensitive data from the victim. This includes screenshots, keystrokes, saved passwords, and files.
See also: Phishing emails distribute Horabot malware in Latin America
Researchers note that the SideWinder group demonstrates remarkable consistency and organizational continuity, without long periods of inactivity. The group, known for targeted espionage on government organizations, now leverages advanced techniques and “smart” malicious payloads to ensure that attacks only hit selected targets.
This campaign underscores the need for continuous vigilance by governmental and strategic entities, especially in areas of high geopolitical interest.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
