APT Sidewinder Hacks into Government and Military Systems to Harvest Login Credentials

A sophisticated cyber espionage campaign attributed to APT Sidewinder has been discovered targeting government and military entities across South Asia and Turkey, using advanced phishing techniques to steal login credentials from high-value targets.

The persistent threat group, believed to originate from South Asia, has successfully compromised multiple defense agencies across Bangladesh, Sri Lanka, Turkey, Nepal, and Pakistan through weaponized documents and malicious links designed to mimic official communications.

Multi-Country Phishing Campaign Targets Critical Infrastructure

Security researchers have identified over a dozen phishing domains specifically crafted to impersonate government agencies, including Bangladesh’s Directorate General of Defence Procurement (DGDP), Directorate General of Forces Intelligence (DGFI), Turkey’s defense contractors ASELSAN and ROKETSAN, and Nepal’s Ministry of Defense.

APT Sidewinder
 Phishing Attack shared by Demon showing the Login page for “Government of Nepal”

The attackers deployed fake Zimbra email login pages hosted on legitimate platforms like Netlify and Pages.dev, making detection significantly more challenging.

The campaign demonstrates remarkable precision in targeting, with phishing sites such as mail-mod-gov-np-account-file-data.netlify.app  dgdp-account-file-data-doc-procuremen.netlify.app designed to replicate authentic government portals closely.

Victims entering credentials on these fake interfaces unknowingly transmitted their login information to attacker-controlled servers at mailbox3-inbox1-bd.com and mailbox-inbox-bd.com. Both resolve to IP address 146.79.118.226 hosted by M247 Europe SRL in Frankfurt, Germany.

Sophisticated Infrastructure Reveals Coordinated Operations

Technical analysis revealed a centralized credential harvesting infrastructure utilizing consistent POST request endpoints across multiple phishing variants.

The attackers employed various PHP scripts, including /3456.php/dgdp12.php/idef.php, and /pol3.php to collect stolen credentials, indicating a template-based deployment model designed for scalability and operational redundancy.

APT Sidewinder
146.70.118.226 records found using Hunt.io intelligence

Infrastructure pivoting through HuntSQL analysis uncovered nine unique phishing URLs targeting different entities but funneling credentials to the same collection servers, demonstrating the campaign’s coordinated nature.

The reuse of visual elements, particularly Zimbra Web Client interfaces with authentic-looking titles, enhanced the credibility of the phishing attempts and likely increased victim success rates.

Security experts recommend implementing multi-factor authentication on all externally accessible services, particularly webmail and VPN systems, while establishing detection rules for DNS resolutions to suspicious domains containing government or military keywords hosted on free platforms.

Organizations should also monitor for HTTP requests exhibiting anomalous Zimbra login paths combined with unexpected POST behavior to external domains.

The discovery underscores APT Sidewinder’s continued evolution and persistence in targeting critical government infrastructure, emphasizing the urgent need for enhanced cybersecurity measures across defense and government sectors in the affected regions.

APT Sidewinder Indicators of Compromise (IOCs)

URLsTitlePOST Request
https://mail.gov.bd.account.file.updatemind52.com/CeqKyQXzZimbra Web Client Sign Inhttps://mailbox-inbox-bd.com/gov.ph
https://webmail.police.gov.bd.updatemind52.com/dPrSJhFPZimbra Web Client Sign Inhttps://mailbox-inbox-bd.com/pol/pol3.php
https://dgdp.cloud.secured.file.updatemind52.com/FOWSMNclDgdp Secured File Systemhttps://mailbox-inbox-bd.com/dgdp/109y.php
https://dgdp-account-file-data-doc-procuremen.netlify.app/Dgdp Secured File Systemhttps://mailbox3-inbox1-bd.com/dgdp12.php
URLsTitlePOST Request
https://mail.gov.bd.account.file.updatemind52.com/CeqKyQXzZimbra Web Client Sign Inhttps://mailbox-inbox-bd.com/gov.ph
https://webmail.police.gov.bd.updatemind52.com/dPrSJhFPZimbra Web Client Sign Inhttps://mailbox-inbox-bd.com/pol/pol3.php
https://dgdp.cloud.secured.file.updatemind52.com/FOWSMNclDgdp Secured File Systemhttps://mailbox-inbox-bd.com/dgdp/109y.php
https://dgdp-account-file-data-doc-procuremen.netlify.app/Dgdp Secured File Systemhttps://mailbox3-inbox1-bd.com/dgdp12.php
URLsTitlePOST Request
https://mail.gov.bd.account.file.updatemind52.com/CeqKyQXzZimbra Web Client Sign Inhttps://mailbox-inbox-bd.com/gov.ph
https://webmail.police.gov.bd.updatemind52.com/dPrSJhFPZimbra Web Client Sign Inhttps://mailbox-inbox-bd.com/pol/pol3.php
https://dgdp.cloud.secured.file.updatemind52.com/FOWSMNclDgdp Secured File Systemhttps://mailbox-inbox-bd.com/dgdp/109y.php
https://dgdp-account-file-data-doc-procuremen.netlify.app/Dgdp Secured File Systemhttps://mailbox3-inbox1-bd.com/dgdp12.php

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories