South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware

Source: The Hacker News
Published: 2025-05-20 12:57
Fetched: 2025-05-20 13:31

Summary

A sophisticated cyber campaign has been detected targeting high-level government institutions in Sri Lanka, Bangladesh, and Pakistan. The threat actor, SideWinder, utilized spear phishing emails and geofenced payloads to ensure the malware only affected specific locations. This campaign exploited old Microsoft Office vulnerabilities, highlighting the persistent threat of outdated software in critical sectors. The use of custom malware by SideWinder indicates a tailored approach to breach national security, emphasizing the need for robust cybersecurity measures. The incident underscores the importance of regular software updates and vigilance against targeted phishing attacks in governmental cybersecurity strategies.

LinkedIn Post

South Asian ministries are under cyberattack by SideWinder APT, exploiting old Office flaws with custom malware. This highlights the need for updated software and strong cybersecurity defenses. #CyberSecurity #APT #ThreatIntelligence #GovernmentSecurity

Content

High-level government institutions in Sri Lanka, Bangladesh, and Pakistan have emerged as the target of a new campaign orchestrated by a threat actor known as SideWinder. "The attackers used spear phishing emails paired with geofenced payloads to ensure that only victims in specific countries received the malicious content," Acronis researchers Santiago Pontiroli, Jozsef Gegeny, and Prakas