Indian APT Intensifies Attacks Against Maritime Facilities

Year

2025

Month

March

Reference number

20250304

Impact area

Shore

Incident location

Egypt, Djibouti, UAE, Bangladesh, Cambodia, Vietman

Incident country

Egypt, Djibouti, UAE, Bangladesh, Cambodia, Vietman

Victim country

Egypt, Djibouti, UAE, Bangladesh, Cambodia, Vietman

Victim identity

Various Entities in the Maritime and Logistics Sectors

Victim Type

Maritime and Logistics

Method

Malware

Attacker country

India

Summary:

As a continuation of their 2024 activities, the Sidewinder APT, has intensified its cyber espionage operations by targeting maritime facilities across multiple regions. Notably, a South Asian port authority received phishing emails with counterfeit maritime safety protocols, resulting in unauthorized network access and potential data compromise. Their attack methodology includes spear-phishing campaigns with the subsequent exploitation of vulnerabilities such as CVE-2017-0199 and CVE-2017-11882, to execute malicious code upon opening of decoy documents. ​Then malicious documents were crafted to exploit vulnerabilities in Microsoft Office’s Equation Editor, facilitating the deployment of backdoor tools.

Reference URL

https://cydome.io/sidewinder-apt-group-intensifies-cyber-attacks-campaign-against-shipping-companies/
https://thehackernews.com/2024/07/new-sidewinder-cyber-attacks-target.html
https://securelist.com/sidewinder-apt-updates-its-toolset-and-targets-nuclear-sector/115847/