SideWinder Hacker Group Launches Fake Outlook and Zimbra Portals to Steal Login Credentials

APT SideWinder, a state-sponsored espionage actor, has escalated its operations in South Asia by deploying more than 50 phishing domains to harvest credentials from government and military entities.

Dubbed “Operation SouthNet,” the campaign leverages free hosting services, including Netlify and Pages.dev, workers.dev, and b4a.run, to present fake Outlook and Zimbra login portals, shifting its primary focus to maritime, aerospace, and telecom sectors in Pakistan and Sri Lanka while maintaining collateral activity in Nepal, Bangladesh, and Myanmar.

Rapid Domain Churn Fuels Credential Theft

Security telemetry reveals SideWinder’s remarkable operational tempo, with the creation of new phishing domains occurring every 3–5 days between August and September 2025.

Pakistan comprises 40% of these domains, with threat actors impersonating key institutions such as SUPARCO (Pakistan’s Space & Upper Atmosphere Research Commission) and the Pakistan Airports Authority.

SideWinder Hacker Group
X tweets related to APT Sidewinder targeting Pakistan & Sri Lanka Government and Military Departments using the Hunt.io Platform

Each phishing site uses direct POST requests, eschewing redirects to exfiltrate credentials to a central server (technologysupport.help), employing JavaScript that Base64-encodes victims’ email addresses for session persistence across multiple phishing stages.

Maritime-Themed Lures Deployed via Weaponized Documents

The group’s latest campaign exhibits a clear maritime emphasis. Analysts uncovered at least 12 weaponized lure documents, packaged as PDFs and ZIP files, bearing titles such as “Training_Program_July_2024.pdf” and “Incident_Report_Gwadar_Port_Complex.pdf.exe.”

Open directories hosted on themegaprovider.ddns.net (47.236.177.123) and gwadarport.ddns.net (31.14.142.50) contained a total of 8 malware samples targeting Pakistan’s marine sector, alongside 33 additional files intended for future deployment.

This activity builds on earlier credential-harvest clusters observed in Sri Lanka’s Navy portals, underscoring SideWinder’s persistent maritime espionage ambitions.

Legacy Infrastructure Overlap Strengthens Attribution

Investigators mapped multiple phishing and malware clusters back to legacy C2 domains, govmm.org, govnp.org, and andc.govaf.org, hosted on IP address 46.183.184.245.

This convergence of historic and newly minted infrastructure, corroborated by Netskope and independent research, confirms the actor’s recycling of command-and-control assets to streamline deployment.

SideWinder Hacker Group
Newly uncovered phishing domains impersonating DGDP and defense portals, highlighting SideWinder’s continued focus on Bangladesh and Turkey

Moreover, pivots on exfiltration domains (drive-nepal-gov.com, myanmar-org-mail.com) and CSRF tokens revealed extensive networks of Outlook- and Zimbra-themed phishing pages across Nepal, Bangladesh, and Myanmar, all bearing the hallmarks of SideWinder.

SideWinder’s adaptive approach, rapid domain turnover, multi-platform hosting, and document-based social engineering pose ongoing risks to South Asian governments and critical sectors.

Immediate mitigation measures include proactive monitoring of free hosting platforms for government-themed domains, ingesting IoCs into SIEM and EDR tools, advanced filtering of suspicious Zimbra/Outlook login attempts, and robust cybersecurity training with an emphasis on document lure recognition.

Regional CERT cooperation is crucial to disrupting SideWinder’s cross-border espionage campaigns and safeguarding sensitive maritime and defense networks.

Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories