Hunt.io Details SideWinder Phishing and Malware Campaign Targeting South Asia

· Original article ↗

Summary

Hunt.io links extensive phishing infrastructure, credential-harvesting portals and malware staging to SideWinder activity targeting government, military and maritime organizations across South Asia.

Key points

  • Hunt.io identified more than 50 malicious domains across Netlify, pages.dev, workers.dev and b4a.run, impersonating government and webmail portals.
  • Targets include government, military, telecom and maritime organizations in Pakistan, Sri Lanka, Nepal, Bangladesh and Myanmar.
  • Lures impersonated Outlook and Zimbra portals and used political, defense and maritime-themed documents to solicit credentials.
  • The report links credential submissions to collection servers including drive-nepal-gov[.]com and technologysupport[.]help.
  • Open directories exposed malware and other files associated with maritime-themed activity and targets in Pakistan and Sri Lanka.
  • Infrastructure overlaps with legacy SideWinder-associated domains and addresses support the attribution; the article notes Singapore impersonation but says direct attribution is unconfirmed.
  • Hunt.io recommends monitoring free hosting platforms, correlating indicators in SIEM and EDR tools, filtering suspicious redirects, and enforcing MFA.

Article Details

Attack Vectors
  • Phishing portals impersonated government, military, maritime, telecom, and other organizations to harvest credentials through fake Outlook, Zimbra, Carbonio, and other webmail or file-access pages.
  • Political, defense, maritime, and port-themed documents were used as lures, directing recipients to counterfeit login pages.
  • Some phishing pages sent stolen credentials directly to collection servers using POST requests; the article reports no redirects for the campaign’s direct-POST credential capture.
  • Malware and decoy files were staged in exposed open directories for later retrieval. The article reports Windows executables, DLLs, archives, and a VBA script among the observed artifacts.
  • In one phishing kit, JavaScript Base64-encoded a victim’s email address and carried it through subsequent phishing stages for session tracking.
Defensive Notes
  • Monitor free-hosting platforms, including Netlify, pages.dev, workers.dev, and b4a.run, for government-themed phishing portals.
  • Ingest and correlate the reported domains, IP addresses, and file hashes in SIEM and EDR systems.
  • Block suspicious redirects and apply filtering against fake Zimbra and Outlook login attempts.
  • Train government and defense personnel to recognize document-based lures that lead to login requests.
  • Enforce MFA and segment critical networks to limit lateral movement after compromise.
  • Coordinate detections and response among regional South Asian CERTs and SOCs.

Indicators of compromise

TypeIndicatorContext
DOMAINandc[.]govaf[.]orgDomain linked in the article to SideWinder-associated infrastructure.
DOMAINcolombo-port[.]ddns[.]netCampaign C2 infrastructure associated with maritime-themed samples.
DOMAINdrive-nepal-gov[.]comCredential-collection server receiving stolen credentials from Nepal-themed phishing pages.
DOMAINgovmm[.]orgLegacy SideWinder-associated infrastructure linked to malware hosting and government-spoofing URLs.
DOMAINgovnp[.]orgDomain linked in the article to SideWinder-associated infrastructure.
DOMAINgwadarport[.]ddns[.]netExposed open-directory and C2 host containing campaign files.
DOMAINmom[.]gov-sg[.]onlinePhishing portal impersonating Singapore’s Ministry of Manpower.
DOMAINmomgovsg[.]infoPhishing portal impersonating Singapore’s Ministry of Manpower.
DOMAINmomgovsg[.]netPhishing portal impersonating Singapore’s Ministry of Manpower.
DOMAINmyanmar-org-mail[.]comAttacker-used credential-collection server for the Myanmar Central Bank phishing page.
DOMAINtechnologysupport[.]helpAttacker-controlled credential-exfiltration server used by Pakistan-themed phishing kits.
DOMAINthemegaprovider[.]ddns[.]netExposed open-directory and C2 host containing campaign files.
HOSTNAMEmail-776f305796709f2d567e6868feaba274-gov-pk-investment[.]pages[.]devFake Zimbra login targeting Pakistan’s Board of Investment.
HOSTNAMEmailcbmgovmm[.]pages[.]devFake Myanmar Central Bank Zimbra login used to harvest credentials.
HOSTNAMEmorning-forest-4fef[.]ethanhunthero125[.]workers[.]devDomain listed among infrastructure associated with the reported maritime campaign.
IPV4159[.]100[.]6[.]5Reported IP address for secure-ntc[.]net, a fake NTC advisory and phishing site.
IPV4193[.]57[.]138[.]22Malicious malware-hosting server associated with govmm[.]org.
IPV431[.]14[.]142[.]50IP hosting an exposed open directory associated with the reported campaign.
IPV446[.]183[.]184[.]245Infrastructure linked to govmm[.]org, govnp[.]org, and andc[.]govaf[.]org.
IPV447[.]236[.]177[.]123IP hosting an exposed open directory with marine-sector campaign samples.
IPV45[.]255[.]113[.]9Malicious server hosting a reported Windows executable.
IPV489[.]46[.]65[.]19C2 address associated with listed campaign samples.
MD500603c207062e8f8576225067a7c5269MD5 of the maritime-themed lure file Training_Program_July_2024.pdf.url.
MD500c1ecc716c9206964b50529661fee7cMD5 of the campaign sample dxgi.dll.
MD504acac204ff3fbd18115982478adb7e5MD5 of gwadardxgi.dll, a sample associated with the campaign.
MD513e321fed4903d136f19ad54b885650bMD5 of the campaign sample pdocumentsdxgi.dll.
MD5487da072770a77a568cb43b7a5f9cdcdMD5 of the campaign sample agent2.malz.
MD55b4eebe67765339f2a4ef7f0cc1d4f44MD5 of the reported Windows executable e0fd3.exe / EdgUpdate.exe.
MD5799b9aa10e223b13577f9685c7808280MD5 of payload_1.zip, a reported malware-related archive hosted with the govmm[.]org infrastructure.
MD57a6723cea87ba7c098f022ad92abf865MD5 of the malicious Windows executable tracked as AdobeUpdateCore.exe and also observed as manarupdate.exe / payload_1.exe.
MD580b8048876db5af4578a6ad9690e2bfaMD5 of a campaign sample named localfile~.
MD5b6fb42a8ff8ea93addf1c3a99abfe10aMD5 of the reported VBA script ThisDocument.txt.
MD5bc5543b39d89cda6832706948945f567MD5 of a campaign sample named localfile~.
MD5c1a5863ad6f31ecc1a9079927c69cbf2MD5 of the maritime-themed archive Navy_Operational_Highlights_2025.zip.
MD5e57860d18607667ca76a5046b97976c3MD5 of the campaign sample lsdxgi.dll.
MD5f3081479986fee38211b28247b185d65MD5 of the campaign sample itrpay.dll.
URLhxxp[:]//blue-term-c168[.]gov-pkgov[.]workers[.]dev/Host linked by the article to SideWinder activity and malware C2.
URLhxxp[:]//maif-piac-aero[.]gov-pkgov[.]workers[.]dev/Credential-harvesting portal impersonating an airline.
URLhxxp[:]//mail-mod-gov-pk[.]pakistan-gov-pk[.]workers[.]dev/Credential-harvesting portal impersonating Pakistan’s Ministry of Defense.
URLhxxp[:]//mail-modp[.]gov-pkgov[.]workers[.]dev/Credential-harvesting portal impersonating Pakistan’s Ministry of Defence Production.
URLhxxp[:]//mail-ntc-net-pk[.]gov-pkgov[.]workers[.]dev/Credential-harvesting portal impersonating Pakistan’s NTC.
URLhxxp[:]//mail[.]pof-gov-pk[.]workers[.]dev/Credential-harvesting portal impersonating Pakistan Ordinance Factories.
URLhxxp[:]//mofagovnp-bm46fjwo[.]b4a[.]run/Phishing site impersonating Nepal’s Ministry of Foreign Affairs.
URLhxxp[:]//pythonscanner[.]gov-pkgov[.]workers[.]dev/Host listed as Pakistan Navy malware C2 infrastructure.
URLhxxp[:]//webmail[.]cybar-net-pk[.]workers[.]dev/Credential-harvesting portal.
URLhxxp[:]//worker-dark-paper-2231[.]gov-pkgov[.]workers[.]dev/Credential-harvesting portal in the reported Pakistan-themed campaign.
URLhxxp[:]//worker-patient-wave-96d1[.]pakistan-gov-pk[.]workers[.]dev/Credential-harvesting portal in the Pakistan-themed infrastructure list.
URLhxxp[:]//workermdxxx[.]naychilin-pk[.]workers[.]dev/Credential-harvesting portal in the reported Pakistan-themed campaign.
URLhxxp[:]//www-nepalgovernment-genz-agendapdf[.]netlify[.]app/Phishing site spoofing a Nepal government email system.

MITRE ATT&CK

People

Threat Actors

Vendors

Products

Tools

Countries

Industries

Related Articles