Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How evolving laws are redefining CISO duty

    October 28, 2025

    AI is reworking medication. May it deliver medical doctors and sufferers collectively?

    October 28, 2025

    10 Python One-Liners for Producing Time Sequence Options

    October 28, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»SideWinder Adopts New ClickOnce-Based mostly Assault Chain Focusing on South Asian Diplomats
    AI Ethics & Regulation

    SideWinder Adopts New ClickOnce-Based mostly Assault Chain Focusing on South Asian Diplomats

    Declan MurphyBy Declan MurphyOctober 28, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    SideWinder Adopts New ClickOnce-Based mostly Assault Chain Focusing on South Asian Diplomats
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Oct 28, 2025Ravie LakshmananCyber Espionage / Malware

    A European embassy positioned within the Indian capital of New Delhi, in addition to a number of organizations in Sri Lanka, Pakistan, and Bangladesh, have emerged because the goal of a brand new marketing campaign orchestrated by a menace actor often called SideWinder in September 2025.

    The exercise “reveals a notable evolution in SideWinder’s TTPs, notably the adoption of a novel PDF and ClickOnce-based an infection chain, along with their beforehand documented Microsoft Phrase exploit vectors,” Trellix researchers Ernesto Fernández Provecho and Pham Duy Phuc mentioned in a report revealed final week.

    The assaults, which concerned sending spear-phishing emails in 4 waves from March via September 2025, are designed to drop malware households comparable to ModuleInstaller and StealerBot to assemble delicate info from compromised hosts.

    Whereas ModuleInstaller serves as a downloader for next-stage payloads, together with StealerBot, the latter is a .NET implant that may launch a reverse shell, ship extra malware, and acquire a variety of knowledge from compromised hosts, together with screenshots, keystrokes, passwords, and recordsdata.

    DFIR Retainer Services

    It needs to be famous that each ModuleInstaller and StealerBot had been first publicly documented by Kaspersky in October 2024 as a part of assaults mounted by the hacking group focusing on high-profile entities and strategic infrastructures within the Center East and Africa.

    As just lately as Might 2025, Acronis revealed SideWinder’s assaults aimed toward authorities establishments in Sri Lanka, Bangladesh, and Pakistan utilizing malware-laden paperwork inclined to recognized Microsoft Workplace flaws to launch a multi-stage assault chain and in the end ship StealerBot.

    The most recent set of assaults, noticed by Trellix submit September 1, 2025, and focusing on Indian embassies, entails the usage of Microsoft Phrase and PDF paperwork in phishing emails with titles comparable to “Inter-ministerial assembly Credentials.pdf” or “India-Pakistan Battle -Strategic and Tactical Evaluation of the Might 2025.docx.” The messages are despatched from the area “mod.gov.bd.pk-mail[.]org” in an try to mimic the Ministry of Protection of Pakistan.

    “The preliminary an infection vector is at all times the identical: a PDF file that can’t be correctly seen by the sufferer or a Phrase doc that comprises some exploit,” Trellix mentioned. “The PDF recordsdata comprise a button that urges the sufferer to obtain and set up the newest model of Adobe Reader to view the doc’s content material.”

    Doing so, nevertheless, triggers the obtain of a ClickOnce software from a distant server (“mofa-gov-bd.filenest[.]stay”), which, when launched, sideloads a malicious DLL (“DEVOBJ.dll”), whereas concurrently launching a decoy PDF doc to the victims.

    The ClickOnce software is a professional executable from MagTek Inc. (“ReaderConfiguration.exe”) that masquerades as Adobe Reader and is signed with a legitimate signature to keep away from elevating any crimson flags. Moreover, requests to the command-and-control (C2) server are region-locked to South Asia and the trail to obtain the payload is dynamically generated, complicating evaluation efforts.

    CIS Build Kits

    The rogue DLL, for its half, is designed to decrypt and launch a .NET loader named ModuleInstaller, which then proceeds to profile the contaminated system and ship the StealerBot malware.

    The findings point out an ongoing effort on the a part of the persistent menace actors to refine their modus operandi and circumvent safety defenses to perform their objectives.

    “The multi-wave phishing campaigns reveal the group’s adaptability in crafting extremely particular lures for varied diplomatic targets, indicating a complicated understanding of geopolitical contexts,” Trellix mentioned. “The constant use of customized malware, comparable to ModuleInstaller and StealerBot, coupled with the intelligent exploitation of professional purposes for side-loading, underscores SideWinder’s dedication to classy evasion methods and espionage aims.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    How evolving laws are redefining CISO duty

    October 28, 2025

    How you can maintain your information protected when transferring giant information – Hackread – Cybersecurity Information, Knowledge Breaches, Tech, AI, Crypto and Extra

    October 28, 2025

    Hackers Goal 81% of Routers with Default Admin Passwords

    October 28, 2025
    Top Posts

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025

    Meta resumes AI coaching utilizing EU person knowledge

    April 18, 2025
    Don't Miss

    How evolving laws are redefining CISO duty

    By Declan MurphyOctober 28, 2025

    CISOs face growing private and felony legal responsibility for improper or incomplete danger administration and…

    AI is reworking medication. May it deliver medical doctors and sufferers collectively?

    October 28, 2025

    10 Python One-Liners for Producing Time Sequence Options

    October 28, 2025

    Teen builds superior robotic hand from LEGO elements

    October 28, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.