Close Menu
TechurzTechurz
    What's Hot

    Get up to $400 off your TechCrunch Disrupt 2026 pass until tomorrow

    August 6, 2026

    Defense tech Hadrian raises $1.37B at $8B valuation

    August 6, 2026

    Omilia raises $67M to scale its customer support platform

    August 6, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Get up to $400 off your TechCrunch Disrupt 2026 pass until tomorrow
    • Defense tech Hadrian raises $1.37B at $8B valuation
    • Omilia raises $67M to scale its customer support platform
    • Get up to $400 off your TechCrunch Disrupt 2026 pass until Friday
    • Trump’s DOJ gains oversight of OpenAI’s green-card employee sponsorships
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - SideWinder Adopts New ClickOnce-Based Attack Chain Targeting South Asian Diplomats
    Cyber Reality

    SideWinder Adopts New ClickOnce-Based Attack Chain Targeting South Asian Diplomats

    TechurzBy TechurzOctober 28, 2025Updated:May 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    ClickOnce-Based Attack Chain
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 28, 2025Ravie LakshmananCyber Espionage / Malware

    A European embassy located in the Indian capital of New Delhi, as well as multiple organizations in Sri Lanka, Pakistan, and Bangladesh, have emerged as the target of a new campaign orchestrated by a threat actor known as SideWinder in September 2025.

    The activity “reveals a notable evolution in SideWinder’s TTPs, particularly the adoption of a novel PDF and ClickOnce-based infection chain, in addition to their previously documented Microsoft Word exploit vectors,” Trellix researchers Ernesto Fernández Provecho and Pham Duy Phuc said in a report published last week.

    The attacks, which involved sending spear-phishing emails in four waves from March through September 2025, are designed to drop malware families such as ModuleInstaller and StealerBot to gather sensitive information from compromised hosts.

    While ModuleInstaller serves as a downloader for next-stage payloads, including StealerBot, the latter is a .NET implant that can launch a reverse shell, deliver additional malware, and collect a wide range of data from compromised hosts, including screenshots, keystrokes, passwords, and files.

    It should be noted that both ModuleInstaller and StealerBot were first publicly documented by Kaspersky in October 2024 as part of attacks mounted by the hacking group targeting high-profile entities and strategic infrastructures in the Middle East and Africa.

    As recently as May 2025, Acronis revealed SideWinder’s attacks aimed at government institutions in Sri Lanka, Bangladesh, and Pakistan using malware-laden documents susceptible to known Microsoft Office flaws to launch a multi-stage attack chain and ultimately deliver StealerBot.

    The latest set of attacks, observed by Trellix post September 1, 2025, and targeting Indian embassies, entails the use of Microsoft Word and PDF documents in phishing emails with titles such as “Inter-ministerial meeting Credentials.pdf” or “India-Pakistan Conflict -Strategic and Tactical Analysis of the May 2025.docx.” The messages are sent from the domain “mod.gov.bd.pk-mail[.]org” in an attempt to mimic the Ministry of Defense of Pakistan.

    “The initial infection vector is always the same: a PDF file that cannot be properly seen by the victim or a Word document that contains some exploit,” Trellix said. “The PDF files contain a button that urges the victim to download and install the latest version of Adobe Reader to view the document’s content.”

    Doing so, however, triggers the download of a ClickOnce application from a remote server (“mofa-gov-bd.filenest[.]live”), which, when launched, sideloads a malicious DLL (“DEVOBJ.dll”), while simultaneously launching a decoy PDF document to the victims.

    The ClickOnce application is a legitimate executable from MagTek Inc. (“ReaderConfiguration.exe”) that masquerades as Adobe Reader and is signed with a valid signature to avoid raising any red flags. Furthermore, requests to the command-and-control (C2) server are region-locked to South Asia and the path to download the payload is dynamically generated, complicating analysis efforts.

    The rogue DLL, for its part, is designed to decrypt and launch a .NET loader named ModuleInstaller, which then proceeds to profile the infected system and deliver the StealerBot malware.

    The findings indicate an ongoing effort on the part of the persistent threat actors to refine their modus operandi and circumvent security defenses to accomplish their goals.

    “The multi-wave phishing campaigns demonstrate the group’s adaptability in crafting highly specific lures for various diplomatic targets, indicating a sophisticated understanding of geopolitical contexts,” Trellix said. “The consistent use of custom malware, such as ModuleInstaller and StealerBot, coupled with the clever exploitation of legitimate applications for side-loading, underscores SideWinder’s commitment to sophisticated evasion techniques and espionage objectives.”

    Adopts Asian Attack Chain ClickOnceBased Diplomats SideWinder South targeting
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDisrupt 2025: Day 1 | TechCrunch
    Next Article Israeli intelligence vets raise $20M to track developer buying signals
    Techurz
    • Website

    Related Posts

    Opinion

    Asian AI startups launch Mythos-like models as Anthropic’s export ban drags on

    June 27, 2026
    Opinion

    Unastella, a South Korean rocket startup that launched from home, raises $24M

    June 1, 2026
    Cyber Reality

    Digital Identity Protection: 7 Hidden Risks Most Users Miss

    May 25, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.