A sophisticated cyber espionage campaign attributed to APT Sidewinder has been discovered targeting government and military entities across South Asia and Turkey, using advanced phishing techniques to steal login credentials from high-value targets.
The persistent threat group, believed to originate from South Asia, has successfully compromised multiple defense agencies across Bangladesh, Sri Lanka, Turkey, Nepal, and Pakistan through weaponized documents and malicious links designed to mimic official communications.
Multi-Country Phishing Campaign Targets Critical Infrastructure
Security researchers have identified over a dozen phishing domains specifically crafted to impersonate government agencies, including Bangladesh’s Directorate General of Defence Procurement (DGDP), Directorate General of Forces Intelligence (DGFI), Turkey’s defense contractors ASELSAN and ROKETSAN, and Nepal’s Ministry of Defense.

The attackers deployed fake Zimbra email login pages hosted on legitimate platforms like Netlify and Pages.dev, making detection significantly more challenging.
The campaign demonstrates remarkable precision in targeting, with phishing sites such as mail-mod-gov-np-account-file-data.netlify.app dgdp-account-file-data-doc-procuremen.netlify.app designed to replicate authentic government portals closely.
Victims entering credentials on these fake interfaces unknowingly transmitted their login information to attacker-controlled servers at mailbox3-inbox1-bd.com and mailbox-inbox-bd.com. Both resolve to IP address 146.79.118.226 hosted by M247 Europe SRL in Frankfurt, Germany.
Sophisticated Infrastructure Reveals Coordinated Operations
Technical analysis revealed a centralized credential harvesting infrastructure utilizing consistent POST request endpoints across multiple phishing variants.
The attackers employed various PHP scripts, including /3456.php, /dgdp12.php, /idef.php, and /pol3.php to collect stolen credentials, indicating a template-based deployment model designed for scalability and operational redundancy.

Infrastructure pivoting through HuntSQL analysis uncovered nine unique phishing URLs targeting different entities but funneling credentials to the same collection servers, demonstrating the campaign’s coordinated nature.
The reuse of visual elements, particularly Zimbra Web Client interfaces with authentic-looking titles, enhanced the credibility of the phishing attempts and likely increased victim success rates.
Security experts recommend implementing multi-factor authentication on all externally accessible services, particularly webmail and VPN systems, while establishing detection rules for DNS resolutions to suspicious domains containing government or military keywords hosted on free platforms.
Organizations should also monitor for HTTP requests exhibiting anomalous Zimbra login paths combined with unexpected POST behavior to external domains.
The discovery underscores APT Sidewinder’s continued evolution and persistence in targeting critical government infrastructure, emphasizing the urgent need for enhanced cybersecurity measures across defense and government sectors in the affected regions.
APT Sidewinder Indicators of Compromise (IOCs)
| URLs | Title | POST Request |
|---|---|---|
| https://mail.gov.bd.account.file.updatemind52.com/CeqKyQXz | Zimbra Web Client Sign In | https://mailbox-inbox-bd.com/gov.ph |
| https://webmail.police.gov.bd.updatemind52.com/dPrSJhFP | Zimbra Web Client Sign In | https://mailbox-inbox-bd.com/pol/pol3.php |
| https://dgdp.cloud.secured.file.updatemind52.com/FOWSMNcl | Dgdp Secured File System | https://mailbox-inbox-bd.com/dgdp/109y.php |
| https://dgdp-account-file-data-doc-procuremen.netlify.app/ | Dgdp Secured File System | https://mailbox3-inbox1-bd.com/dgdp12.php |
| URLs | Title | POST Request |
|---|---|---|
| https://mail.gov.bd.account.file.updatemind52.com/CeqKyQXz | Zimbra Web Client Sign In | https://mailbox-inbox-bd.com/gov.ph |
| https://webmail.police.gov.bd.updatemind52.com/dPrSJhFP | Zimbra Web Client Sign In | https://mailbox-inbox-bd.com/pol/pol3.php |
| https://dgdp.cloud.secured.file.updatemind52.com/FOWSMNcl | Dgdp Secured File System | https://mailbox-inbox-bd.com/dgdp/109y.php |
| https://dgdp-account-file-data-doc-procuremen.netlify.app/ | Dgdp Secured File System | https://mailbox3-inbox1-bd.com/dgdp12.php |
| URLs | Title | POST Request |
|---|---|---|
| https://mail.gov.bd.account.file.updatemind52.com/CeqKyQXz | Zimbra Web Client Sign In | https://mailbox-inbox-bd.com/gov.ph |
| https://webmail.police.gov.bd.updatemind52.com/dPrSJhFP | Zimbra Web Client Sign In | https://mailbox-inbox-bd.com/pol/pol3.php |
| https://dgdp.cloud.secured.file.updatemind52.com/FOWSMNcl | Dgdp Secured File System | https://mailbox-inbox-bd.com/dgdp/109y.php |
| https://dgdp-account-file-data-doc-procuremen.netlify.app/ | Dgdp Secured File System | https://mailbox3-inbox1-bd.com/dgdp12.php |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates