Zscaler Threat Hunting has uncovered a sophisticated espionage campaign targeting Indian entities through fake “Income Tax Department” websites.
The operation, believed to be linked to the SideWinder APT group, also known as Rattlesnake or APT-C-17, uses bureaucratic lures and advanced evasion tactics to compromise victims across India and neighboring countries in the Asia-Pacific region.
According to Zscaler, the campaign primarily targets enterprises in the Services, Retail, Telecommunications, and Healthcare sectors.
Attackers lure victims with phishing emails and redirect them to fraudulent portals hosted on obscure domains such as gfmqvip[.]vip.
From there, users are tricked into downloading a malicious file, Inspection.zip, disguised as an official document review package from the Indian Income Tax Department.
The archive contains a legitimate Microsoft Defender file (SenseCE.exe), a malicious DLL (MpGear.dll), and decoy certificates.
When executed, the legitimate binary performs DLL side-loading, loading the malicious DLL into memory to execute additional payloads without triggering antivirus alarms.
Living Off the Land and Cloud Services
SideWinder’s latest tactics focus on stealth and persistence. By abusing trusted system files such as Microsoft Defender executables, the threat actor effectively “lives off the land,” blending into normal system behavior.
The use of URL shorteners like surl[.]li and public file-sharing services such as GoFile.io further complicates network-level detection, as these platforms are often considered safe.
Zscaler’s telemetry revealed that victims’ systems contacted timeapi[.]io and worldtimeapi[.]org to check local time zones, a geofencing technique that ensures the malware activates only in South Asian regions.

The attackers then connected to remote command-and-control (C2) servers, including 8[.]217[.]152[.]225 and 180[.]178[.]56[.]230, to download a secondary payload named mysetup.exe, a resident espionage implant configured to mimic Chinese enterprise software activity.
These operations show SideWinder’s evolving toolkit, designed to bypass Endpoint Detection and Response (EDR) systems and exploit trusted cloud platforms for covert communications.
Zscaler recommends strict inspection policies on SSL/TLS traffic, blocking access to known C2 servers, and monitoring suspicious use of legitimate executables, such as SenseCE.exe, from non-standard directories. Organizations should also quarantine archive files (.zip) from unverified sources.
The report underscores that SideWinder continues to adapt its tactics to evade detection, mixing credible government impersonations with low-cost infrastructure and indigenous malware implants to compromise regional targets.
Zscaler urged organizations across South Asia to strengthen threat-hunting operations, as detection of such campaigns often begins not with alerts but with active, hypothesis-driven hunting.
Follow us on Google News , LinkedIn and X to Get More Instant Updates, Set Cyberpress as a Preferred Source in Google.