CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

SideWinder Adopts ClickOnce-Based Attack Chain Targeting South Asian Diplomats

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

SideWinder, a persistent threat actor, has targeted South Asian diplomats with a new campaign. The attacks, conducted from March through September 2025, used spear-phishing emails to deliver malware. The infection chain involved PDF and ClickOnce-based vectors, along with previously documented Microsoft Word exploits. The campaign targeted embassies and organizations in India, Sri Lanka, Pakistan, and Bangladesh. The malware families deployed include ModuleInstaller and StealerBot, which are used to gather sensitive information from compromised hosts. The attacks highlight SideWinder's evolving tactics and their focus on sophisticated evasion techniques and espionage objectives.

Timeline

  1. 28.10.2025 06:01 1 articles · 13d ago

    SideWinder Targets South Asian Diplomats with New ClickOnce-Based Attack Chain

    From March through September 2025, SideWinder conducted a campaign targeting South Asian diplomats. The attacks used spear-phishing emails with PDF and ClickOnce-based infection chains to deliver malware families such as ModuleInstaller and StealerBot. The campaign targeted embassies and organizations in India, Sri Lanka, Pakistan, and Bangladesh, demonstrating the group's adaptability and sophisticated understanding of geopolitical contexts.

    Show sources

Information Snippets