Operation SouthNet: SideWinder Expands Phishing and Malware Operations in South Asia
Oct. 6, 2025, 11:03 a.m.
Description
APT SideWinder has launched a new targeted operation dubbed Operation SouthNet, focusing on the maritime sector in South Asia, particularly Pakistan and Sri Lanka. The group leverages free hosting platforms to deploy credential-harvesting portals and weaponized lure documents, while staging malware in open directories. Over 50 malicious domains were uncovered across various platforms, with Pakistan accounting for 40% of the identified domains. The campaign utilizes maritime and port-themed lures to target government and military entities. SideWinder's infrastructure overlaps with legacy C2 assets, indicating recycling across multiple years. The group maintains a high operational tempo, with new phishing domains emerging every 3-5 days.
Tags
Date
- Created: Oct. 6, 2025, 8:11 a.m.
- Published: Oct. 6, 2025, 8:11 a.m.
- Modified: Oct. 6, 2025, 11:03 a.m.
Additional Informations
- Defense
- Transportation
- Government
- Myanmar
- Singapore
- Sri Lanka
- Nepal
- Bangladesh
- Pakistan