Operation SouthNet: SideWinder Expands Phishing and Malware Operations in South Asia

Oct. 6, 2025, 11:03 a.m.

Description

APT SideWinder has launched a new targeted operation dubbed Operation SouthNet, focusing on the maritime sector in South Asia, particularly Pakistan and Sri Lanka. The group leverages free hosting platforms to deploy credential-harvesting portals and weaponized lure documents, while staging malware in open directories. Over 50 malicious domains were uncovered across various platforms, with Pakistan accounting for 40% of the identified domains. The campaign utilizes maritime and port-themed lures to target government and military entities. SideWinder's infrastructure overlaps with legacy C2 assets, indicating recycling across multiple years. The group maintains a high operational tempo, with new phishing domains emerging every 3-5 days.

Date

  • Created: Oct. 6, 2025, 8:11 a.m.
  • Published: Oct. 6, 2025, 8:11 a.m.
  • Modified: Oct. 6, 2025, 11:03 a.m.

Attack Patterns

  • agent2.malz
  • gwadardxgi.dll
  • EdgUpdate.exe
  • AdobeUpdateCore.exe
  • Sidewinder

Additional Informations

  • Defense
  • Transportation
  • Government
  • Myanmar
  • Singapore
  • Sri Lanka
  • Nepal
  • Bangladesh
  • Pakistan