The SideWinder group has become infamous for targeting the South Asian region and its surrounding countries. A server is being used to deliver a malicious LNK file and host multiple credential phishing pages. These pages were copied from their victims’ webmail login pages and subsequently modified for phishing. Further activities are propagated via spear-phishing attacks. In addition, multiple Android APK files were also found on the phishing server.
The group’s targets include multiple government and military units, mainly in Nepal and Afghanistan. After the gathered credentials are sent, some of the phishing pages will redirect victims to different documents or news pages. The themes and topics of these pages and documents are related to either Covid-19 or recent territory disputes between Nepal, Pakistan, India, and China. Furthermore, it seems that these lures are distributed via phishing links. Several different samples from the campaign include:
Moreover, the Android applications still seem to be under the initial development phase as they are basic, still use the default Android icons, and have no practical function for users. Two applications among them are named “My First APP” and “Opinion Poll,” that seemingly have no malicious behavior.