Hunt.io Details SideWinder Phishing and Malware Campaign Targeting South Asia

Summary
Hunt.io links extensive phishing infrastructure, credential-harvesting portals and malware staging to SideWinder activity targeting government, military and maritime organizations across South Asia.
Key points
- Hunt.io identified more than 50 malicious domains across Netlify, pages.dev, workers.dev and b4a.run, impersonating government and webmail portals.
- Targets include government, military, telecom and maritime organizations in Pakistan, Sri Lanka, Nepal, Bangladesh and Myanmar.
- Lures impersonated Outlook and Zimbra portals and used political, defense and maritime-themed documents to solicit credentials.
- The report links credential submissions to collection servers including drive-nepal-gov[.]com and technologysupport[.]help.
- Open directories exposed malware and other files associated with maritime-themed activity and targets in Pakistan and Sri Lanka.
- Infrastructure overlaps with legacy SideWinder-associated domains and addresses support the attribution; the article notes Singapore impersonation but says direct attribution is unconfirmed.
- Hunt.io recommends monitoring free hosting platforms, correlating indicators in SIEM and EDR tools, filtering suspicious redirects, and enforcing MFA.
Article Details
- Attack Vectors
- Phishing portals impersonated government, military, maritime, telecom, and other organizations to harvest credentials through fake Outlook, Zimbra, Carbonio, and other webmail or file-access pages.
- Political, defense, maritime, and port-themed documents were used as lures, directing recipients to counterfeit login pages.
- Some phishing pages sent stolen credentials directly to collection servers using POST requests; the article reports no redirects for the campaign’s direct-POST credential capture.
- Malware and decoy files were staged in exposed open directories for later retrieval. The article reports Windows executables, DLLs, archives, and a VBA script among the observed artifacts.
- In one phishing kit, JavaScript Base64-encoded a victim’s email address and carried it through subsequent phishing stages for session tracking.
- Defensive Notes
- Monitor free-hosting platforms, including Netlify, pages.dev, workers.dev, and b4a.run, for government-themed phishing portals.
- Ingest and correlate the reported domains, IP addresses, and file hashes in SIEM and EDR systems.
- Block suspicious redirects and apply filtering against fake Zimbra and Outlook login attempts.
- Train government and defense personnel to recognize document-based lures that lead to login requests.
- Enforce MFA and segment critical networks to limit lateral movement after compromise.
- Coordinate detections and response among regional South Asian CERTs and SOCs.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | andc[.]govaf[.]org | Domain linked in the article to SideWinder-associated infrastructure. |
| DOMAIN | colombo-port[.]ddns[.]net | Campaign C2 infrastructure associated with maritime-themed samples. |
| DOMAIN | drive-nepal-gov[.]com | Credential-collection server receiving stolen credentials from Nepal-themed phishing pages. |
| DOMAIN | govmm[.]org | Legacy SideWinder-associated infrastructure linked to malware hosting and government-spoofing URLs. |
| DOMAIN | govnp[.]org | Domain linked in the article to SideWinder-associated infrastructure. |
| DOMAIN | gwadarport[.]ddns[.]net | Exposed open-directory and C2 host containing campaign files. |
| DOMAIN | mom[.]gov-sg[.]online | Phishing portal impersonating Singapore’s Ministry of Manpower. |
| DOMAIN | momgovsg[.]info | Phishing portal impersonating Singapore’s Ministry of Manpower. |
| DOMAIN | momgovsg[.]net | Phishing portal impersonating Singapore’s Ministry of Manpower. |
| DOMAIN | myanmar-org-mail[.]com | Attacker-used credential-collection server for the Myanmar Central Bank phishing page. |
| DOMAIN | technologysupport[.]help | Attacker-controlled credential-exfiltration server used by Pakistan-themed phishing kits. |
| DOMAIN | themegaprovider[.]ddns[.]net | Exposed open-directory and C2 host containing campaign files. |
| HOSTNAME | mail-776f305796709f2d567e6868feaba274-gov-pk-investment[.]pages[.]dev | Fake Zimbra login targeting Pakistan’s Board of Investment. |
| HOSTNAME | mailcbmgovmm[.]pages[.]dev | Fake Myanmar Central Bank Zimbra login used to harvest credentials. |
| HOSTNAME | morning-forest-4fef[.]ethanhunthero125[.]workers[.]dev | Domain listed among infrastructure associated with the reported maritime campaign. |
| IPV4 | 159[.]100[.]6[.]5 | Reported IP address for secure-ntc[.]net, a fake NTC advisory and phishing site. |
| IPV4 | 193[.]57[.]138[.]22 | Malicious malware-hosting server associated with govmm[.]org. |
| IPV4 | 31[.]14[.]142[.]50 | IP hosting an exposed open directory associated with the reported campaign. |
| IPV4 | 46[.]183[.]184[.]245 | Infrastructure linked to govmm[.]org, govnp[.]org, and andc[.]govaf[.]org. |
| IPV4 | 47[.]236[.]177[.]123 | IP hosting an exposed open directory with marine-sector campaign samples. |
| IPV4 | 5[.]255[.]113[.]9 | Malicious server hosting a reported Windows executable. |
| IPV4 | 89[.]46[.]65[.]19 | C2 address associated with listed campaign samples. |
| MD5 | 00603c207062e8f8576225067a7c5269 | MD5 of the maritime-themed lure file Training_Program_July_2024.pdf.url. |
| MD5 | 00c1ecc716c9206964b50529661fee7c | MD5 of the campaign sample dxgi.dll. |
| MD5 | 04acac204ff3fbd18115982478adb7e5 | MD5 of gwadardxgi.dll, a sample associated with the campaign. |
| MD5 | 13e321fed4903d136f19ad54b885650b | MD5 of the campaign sample pdocumentsdxgi.dll. |
| MD5 | 487da072770a77a568cb43b7a5f9cdcd | MD5 of the campaign sample agent2.malz. |
| MD5 | 5b4eebe67765339f2a4ef7f0cc1d4f44 | MD5 of the reported Windows executable e0fd3.exe / EdgUpdate.exe. |
| MD5 | 799b9aa10e223b13577f9685c7808280 | MD5 of payload_1.zip, a reported malware-related archive hosted with the govmm[.]org infrastructure. |
| MD5 | 7a6723cea87ba7c098f022ad92abf865 | MD5 of the malicious Windows executable tracked as AdobeUpdateCore.exe and also observed as manarupdate.exe / payload_1.exe. |
| MD5 | 80b8048876db5af4578a6ad9690e2bfa | MD5 of a campaign sample named localfile~. |
| MD5 | b6fb42a8ff8ea93addf1c3a99abfe10a | MD5 of the reported VBA script ThisDocument.txt. |
| MD5 | bc5543b39d89cda6832706948945f567 | MD5 of a campaign sample named localfile~. |
| MD5 | c1a5863ad6f31ecc1a9079927c69cbf2 | MD5 of the maritime-themed archive Navy_Operational_Highlights_2025.zip. |
| MD5 | e57860d18607667ca76a5046b97976c3 | MD5 of the campaign sample lsdxgi.dll. |
| MD5 | f3081479986fee38211b28247b185d65 | MD5 of the campaign sample itrpay.dll. |
| URL | hxxp[:]//blue-term-c168[.]gov-pkgov[.]workers[.]dev/ | Host linked by the article to SideWinder activity and malware C2. |
| URL | hxxp[:]//maif-piac-aero[.]gov-pkgov[.]workers[.]dev/ | Credential-harvesting portal impersonating an airline. |
| URL | hxxp[:]//mail-mod-gov-pk[.]pakistan-gov-pk[.]workers[.]dev/ | Credential-harvesting portal impersonating Pakistan’s Ministry of Defense. |
| URL | hxxp[:]//mail-modp[.]gov-pkgov[.]workers[.]dev/ | Credential-harvesting portal impersonating Pakistan’s Ministry of Defence Production. |
| URL | hxxp[:]//mail-ntc-net-pk[.]gov-pkgov[.]workers[.]dev/ | Credential-harvesting portal impersonating Pakistan’s NTC. |
| URL | hxxp[:]//mail[.]pof-gov-pk[.]workers[.]dev/ | Credential-harvesting portal impersonating Pakistan Ordinance Factories. |
| URL | hxxp[:]//mofagovnp-bm46fjwo[.]b4a[.]run/ | Phishing site impersonating Nepal’s Ministry of Foreign Affairs. |
| URL | hxxp[:]//pythonscanner[.]gov-pkgov[.]workers[.]dev/ | Host listed as Pakistan Navy malware C2 infrastructure. |
| URL | hxxp[:]//webmail[.]cybar-net-pk[.]workers[.]dev/ | Credential-harvesting portal. |
| URL | hxxp[:]//worker-dark-paper-2231[.]gov-pkgov[.]workers[.]dev/ | Credential-harvesting portal in the reported Pakistan-themed campaign. |
| URL | hxxp[:]//worker-patient-wave-96d1[.]pakistan-gov-pk[.]workers[.]dev/ | Credential-harvesting portal in the Pakistan-themed infrastructure list. |
| URL | hxxp[:]//workermdxxx[.]naychilin-pk[.]workers[.]dev/ | Credential-harvesting portal in the reported Pakistan-themed campaign. |
| URL | hxxp[:]//www-nepalgovernment-genz-agendapdf[.]netlify[.]app/ | Phishing site spoofing a Nepal government email system. |
MITRE ATT&CK
People
Threat Actors
Vendors
Products
Carboniohttpx://www-foreignaffairs-nepal-com[.]netlify[.]app/ Carbonio Webmail Login -Netlifywe label Operation SouthNet, attributed to APT SideWinder. The actor leverages free hosting platforms (Netlify, pages.dev, workers.dev, b4a.run) to deploy credential-harvesting portals and weaponized lure documents,OutlookPhishing Infrastructure at Scale: Over 50+ malicious domains uncovered across Netlify, pages.dev, workers.dev, and b4a.run, hosting fake Outlook/Zimbra portals and credential harvesting pages.ZimbraPhishing Infrastructure at Scale: Over 50+ malicious domains uncovered across Netlify, pages.dev, workers.dev, and b4a.run, hosting fake Outlook/Zimbra portals and credential harvesting pages.
Tools
Countries
BangladeshThe campaign shows an operational focus on maritime and port-themed lures and targets government and military entities in Pakistan and Sri Lanka, with supporting activity touching Nepal, Bangladesh, and Myanmar.MyanmarThe campaign shows an operational focus on maritime and port-themed lures and targets government and military entities in Pakistan and Sri Lanka, with supporting activity touching Nepal, Bangladesh, and Myanmar.NepalThe campaign shows an operational focus on maritime and port-themed lures and targets government and military entities in Pakistan and Sri Lanka, with supporting activity touching Nepal, Bangladesh, and Myanmar.Pakistanand credential-harvesting activities, the group has now shifted focus toward the maritime sector, with Pakistan and Sri Lanka emerging as primary targets.Singaporesector in Pakistan and Sri Lanka.And while most activity stays in South Asia, we also found spillover: Singapore's Ministry of Manpower impersonated with the same templates.Sri Lankaactivities, the group has now shifted focus toward the maritime sector, with Pakistan and Sri Lanka emerging as primary targets.Turkeyservers. The operation primarily targeted government and defense organizations in Nepal, Bangladesh, and Turkey, using fake Zimbra webmail and secure portal login pages.
Industries
AerospaceThat overlap isn't just historical. The same playbook shows up immediately in Pakistan, where SideWinder shifts its focus to aerospace, research, and telecom institutionsDefenseLure Documents: At least 12 weaponized documents were observed between August and September 2025, themed around ministerial committees, bilateral visits, and defense procurements.financeHunt.io uncovered an attack targeting Nepal's Ministry of Finance using a fake Outlook webmail login page at httpx://mall-ministryoffinance-np[.]netlify[.]app/ hosted on Netlify (resolving to 98.84.224.111).GovernmentThe campaign shows an operational focus on maritime and port-themed lures and targets government and military entities in Pakistan and Sri Lanka, with supporting activity touching Nepal, Bangladesh, and Myanmar.Maritimewith extensive phishing and credential-harvesting activities, the group has now shifted focus toward the maritime sector, with Pakistan and Sri Lanka emerging as primary targets.MilitaryThe campaign shows an operational focus on maritime and port-themed lures and targets government and military entities in Pakistan and Sri Lanka, with supporting activity touching Nepal, Bangladesh, and Myanmar.ResearchBoth have previously been associated with APT SideWinder, as highlighted in Netskope's research and corroborated by independent security researcher @wa1Ile. These overlaps strengthen the assessmentTelecommunications