Year2025 |
MonthMarch |
Reference number20250304 |
Impact areaShore |
Incident locationEgypt, Djibouti, UAE, Bangladesh, Cambodia, Vietman |
Incident countryEgypt, Djibouti, UAE, Bangladesh, Cambodia, Vietman |
Victim countryEgypt, Djibouti, UAE, Bangladesh, Cambodia, Vietman |
Victim identityVarious Entities in the Maritime and Logistics Sectors |
Victim TypeMaritime and Logistics |
MethodMalware |
Attacker countryIndia |
As a continuation of their 2024 activities, the Sidewinder APT, has intensified its cyber espionage operations by targeting maritime facilities across multiple regions. Notably, a South Asian port authority received phishing emails with counterfeit maritime safety protocols, resulting in unauthorized network access and potential data compromise. Their attack methodology includes spear-phishing campaigns with the subsequent exploitation of vulnerabilities such as CVE-2017-0199 and CVE-2017-11882, to execute malicious code upon opening of decoy documents. Then malicious documents were crafted to exploit vulnerabilities in Microsoft Office’s Equation Editor, facilitating the deployment of backdoor tools.