{"id":19070,"date":"2022-02-17T06:40:04","date_gmt":"2022-02-17T06:40:04","guid":{"rendered":"https:\/\/nsfocusglobal.com\/?p=19070"},"modified":"2026-04-17T18:07:45","modified_gmt":"2026-04-17T18:07:45","slug":"indias-national-apt-organization-sidewinder-launched-phishing-attacks","status":"publish","type":"post","link":"https:\/\/nsfocusglobal.com\/pt-br\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/","title":{"rendered":"India&#8217;s National APT Organization SideWinder Launched Phishing Attacks"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p>Recently, NSFOCUS Labs discovered that the South Asian APT organization SideWinder launched phishing attacks with documents used Pakistan National Day-related content as the bait. The domain name of command and control (C2) server was forged as a Pakistani government website. Since SideWinder &acirc;&euro;&tilde;s targets include Pakistan and China, it has always been considered an APT group from India.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Attack activity analysis<\/h2>\n\n\n\n<p><strong>Decoy Documentation<\/strong><\/p>\n\n\n\n<p>The threat actor used RTF documents Pakistan National Day-related topic to lure the target to open it. The Pakistan National Day is on March 23 every year, just over a month left from now. The body is an invitation to participate in the celebration and prepare a patriotic speech.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217a.jpg\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"660\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217a-1024x660.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-19071\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217a-1024x660.jpg 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217a-300x193.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217a-768x495.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217a-200x129.jpg 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217a.jpg 1077w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption>Phishing document<\/figcaption><\/figure>\n\n\n\n<p>However, the time mentioned in the text is 2021, which may be because the attacker were not careful enough in making the bait, and directly quoted the content of last year.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217b.jpg\"><img decoding=\"async\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217b.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-19073\" width=\"246\" height=\"376\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217b.jpg 491w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217b-196x300.jpg 196w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217b-200x306.jpg 200w\" sizes=\"(max-width: 246px) 100vw, 246px\" \/><\/a><figcaption> Source: phcsingapore.org <\/figcaption><\/figure><\/div>\n\n\n\n<p><strong>Attack process<\/strong><\/p>\n\n\n\n<p>When the document is opened, a formula editor vulnerability (CVE-2017-11882) embedded in the document is exploited to trigger a set of codes in JavaScript and load an executable a .NET file in memory after decoding for the purpose of connecting the C2 server to download the subsequent files.<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-full is-resized\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217c.jpg\"><img decoding=\"async\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217c.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-19075\" width=\"449\" height=\"150\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217c.jpg 598w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217c-300x100.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217c-200x67.jpg 200w\" sizes=\"(max-width: 449px) 100vw, 449px\" \/><\/a><figcaption>Embedded content in a phishing RTF<\/figcaption><\/figure><\/div>\n\n\n\n<p>Instead of using powershell, the attacker used ActiveXObject and DotNetToJScript method to load. NET program, which is probably because of concern about detection of security software on the target hosts.<\/p>\n\n\n\n<p>Codes in JavaScript<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217d.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"984\" height=\"270\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217d.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-19077\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217d.jpg 984w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217d-300x82.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217d-768x211.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217d-200x55.jpg 200w\" sizes=\"(max-width: 984px) 100vw, 984px\" \/><\/a><\/figure><\/div>\n\n\n\n<p>.NET Components:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217e.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"995\" height=\"267\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217e.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-19079\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217e.jpg 995w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217e-300x81.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217e-768x206.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217e-200x54.jpg 200w\" sizes=\"(max-width: 995px) 100vw, 995px\" \/><\/a><\/figure><\/div>\n\n\n\n<p><strong>Command and control (C2) server<\/strong><\/p>\n\n\n\n<p>The domain name of C2 server used by the attacker contains the string mofa-gov-pk, directing to the website of the Ministry of Foreign Affairs of the Pakistan. Using the whitelist mechanism and the habit of people reading domain names from left to right, the attacker added a normal domain name after others and tried to escape detection by the multi-level domain name.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217f.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217f-1024x583.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-19081\" width=\"512\" height=\"292\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217f-1024x583.jpg 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217f-300x171.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217f-768x437.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217f-200x114.jpg 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217f.jpg 1200w\" sizes=\"(max-width: 512px) 100vw, 512px\" \/><\/a><figcaption>The official website of the Ministry of Foreign Affairs of Pakistan<\/figcaption><\/figure><\/div>\n\n\n\n<p><strong>Conclusion<\/strong><\/p>\n\n\n\n<p>In recent years, border disputes between South Asian countries have continued, and APT attacks have occurred from time to time. Powershell has attracted much attention because of its convenient loading of .NET components, but Sidewinder uses DotNetToJScript instead of powershell, which requires defenders to pay more attention.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Knowledge Graph of SideWinder<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217g.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"405\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217g-1024x405.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-19083\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217g-1024x405.jpg 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217g-300x119.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217g-768x304.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217g-200x79.jpg 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/02\/0217g.jpg 1089w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Associated IoCs detected using NSFOCUS Threat Intelligence (NTI)<\/h2>\n\n\n\n<p>MD 5 (section):<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>2db1ddd612010baf707bafe71cff3ecd<\/td><\/tr><tr><td>2f4adea4665929d8a4b6d936c2f120c1<\/td><\/tr><tr><td>5ac0946ed702e6d01e699b8060fc907e<\/td><\/tr><tr><td>5aec4856ebe472b53a74cbe210b32a48<\/td><\/tr><tr><td>5e575681a2eeed2036e556f7733d4e7c<\/td><\/tr><tr><td>6a85fe72f098db4de4b2ae11f614e6b9<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>Overview Recently, NSFOCUS Labs discovered that the South Asian APT organization SideWinder launched phishing attacks with documents used Pakistan National Day-related content as the bait. The domain name of command and control (C2) server was forged as a Pakistani government website. Since SideWinder &acirc;&euro;&tilde;s targets include Pakistan and China, it has always been considered an [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":17564,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[3,6],"tags":[93,582,649],"class_list":["post-19070","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-emergency-response","tag-apt","tag-phishing","tag-sidewinder"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>India&#039;s National APT Organization SideWinder Launched Phishing Attacks - NSFOCUS<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"India&#039;s National APT Organization SideWinder Launched Phishing Attacks - NSFOCUS\" \/>\n<meta property=\"og:description\" content=\"Overview Recently, NSFOCUS Labs discovered that the South Asian APT organization SideWinder launched phishing attacks with documents used Pakistan\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"NSFOCUS\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-17T06:40:04+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-17T18:07:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/malware.jpg\" \/>\n<meta name=\"author\" content=\"Jie Ji\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"India&#039;s National APT Organization SideWinder Launched Phishing Attacks - NSFOCUS\" \/>\n<meta name=\"twitter:description\" content=\"Overview Recently, NSFOCUS Labs discovered that the South Asian APT organization SideWinder launched phishing attacks with documents used Pakistan\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/malware.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jie Ji\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/\"},\"author\":{\"name\":\"Jie Ji\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/person\\\/1077d8fcd7e52c96f17a33b63a0d157b\"},\"headline\":\"India&#8217;s National APT Organization SideWinder Launched Phishing Attacks\",\"datePublished\":\"2022-02-17T06:40:04+00:00\",\"dateModified\":\"2026-04-17T18:07:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/\"},\"wordCount\":440,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/malware.jpg\",\"keywords\":[\"APT\",\"Phishing\",\"SideWInder\"],\"articleSection\":[\"Blog\",\"Emergency Response\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/\",\"name\":\"India's National APT Organization SideWinder Launched Phishing Attacks - NSFOCUS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/malware.jpg\",\"datePublished\":\"2022-02-17T06:40:04+00:00\",\"dateModified\":\"2026-04-17T18:07:45+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/malware.jpg\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/malware.jpg\",\"width\":609,\"height\":366,\"caption\":\"Hooded figure with binary code overlay.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nsfocusglobal.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"India&#8217;s National APT Organization SideWinder Launched Phishing Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#website\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/\",\"name\":\"NSFOCUS\",\"description\":\"Security Made Smart and Simple\",\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nsfocusglobal.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#organization\",\"name\":\"NSFOCUS\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"width\":248,\"height\":36,\"caption\":\"NSFOCUS\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/#\\\/schema\\\/person\\\/1077d8fcd7e52c96f17a33b63a0d157b\",\"name\":\"Jie Ji\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g\",\"caption\":\"Jie Ji\"},\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/author\\\/jji\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"India's National APT Organization SideWinder Launched Phishing Attacks - NSFOCUS","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/","og_locale":"pt_BR","og_type":"article","og_title":"India's National APT Organization SideWinder Launched Phishing Attacks - NSFOCUS","og_description":"Overview Recently, NSFOCUS Labs discovered that the South Asian APT organization SideWinder launched phishing attacks with documents used Pakistan","og_url":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/","og_site_name":"NSFOCUS","article_published_time":"2022-02-17T06:40:04+00:00","article_modified_time":"2026-04-17T18:07:45+00:00","og_image":[{"url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/malware.jpg","type":"","width":"","height":""}],"author":"Jie Ji","twitter_card":"summary_large_image","twitter_title":"India's National APT Organization SideWinder Launched Phishing Attacks - NSFOCUS","twitter_description":"Overview Recently, NSFOCUS Labs discovered that the South Asian APT organization SideWinder launched phishing attacks with documents used Pakistan","twitter_image":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/malware.jpg","twitter_misc":{"Escrito por":"Jie Ji","Est. tempo de leitura":"4 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/#article","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/"},"author":{"name":"Jie Ji","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/person\/1077d8fcd7e52c96f17a33b63a0d157b"},"headline":"India&#8217;s National APT Organization SideWinder Launched Phishing Attacks","datePublished":"2022-02-17T06:40:04+00:00","dateModified":"2026-04-17T18:07:45+00:00","mainEntityOfPage":{"@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/"},"wordCount":440,"commentCount":0,"publisher":{"@id":"https:\/\/nsfocusglobal.com\/#organization"},"image":{"@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/malware.jpg","keywords":["APT","Phishing","SideWInder"],"articleSection":["Blog","Emergency Response"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/","url":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/","name":"India's National APT Organization SideWinder Launched Phishing Attacks - NSFOCUS","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/#primaryimage"},"image":{"@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/malware.jpg","datePublished":"2022-02-17T06:40:04+00:00","dateModified":"2026-04-17T18:07:45+00:00","breadcrumb":{"@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/#primaryimage","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/malware.jpg","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/07\/malware.jpg","width":609,"height":366,"caption":"Hooded figure with binary code overlay."},{"@type":"BreadcrumbList","@id":"https:\/\/nsfocusglobal.com\/indias-national-apt-organization-sidewinder-launched-phishing-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nsfocusglobal.com\/"},{"@type":"ListItem","position":2,"name":"India&#8217;s National APT Organization SideWinder Launched Phishing Attacks"}]},{"@type":"WebSite","@id":"https:\/\/nsfocusglobal.com\/#website","url":"https:\/\/nsfocusglobal.com\/","name":"NSFOCUS","description":"Security Made Smart and Simple","publisher":{"@id":"https:\/\/nsfocusglobal.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nsfocusglobal.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/nsfocusglobal.com\/#organization","name":"NSFOCUS","url":"https:\/\/nsfocusglobal.com\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/logo\/image\/","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","width":248,"height":36,"caption":"NSFOCUS"},"image":{"@id":"https:\/\/nsfocusglobal.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/nsfocusglobal.com\/#\/schema\/person\/1077d8fcd7e52c96f17a33b63a0d157b","name":"Jie Ji","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g","caption":"Jie Ji"},"url":"https:\/\/nsfocusglobal.com\/pt-br\/author\/jji\/"}]}},"_links":{"self":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/19070","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/comments?post=19070"}],"version-history":[{"count":0,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/19070\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media\/17564"}],"wp:attachment":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media?parent=19070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/categories?post=19070"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/tags?post=19070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}