RAZOR_TIGER__2020__SideWinder_Uses_South_Asian_Issues_for_Spear_Phishing_Mobile_Attacks.pdf
ID: 388ea93c-6f78-41c1-ac66-19551c1cd944
STIX ID: report--388ea93c-6f78-41c1-ac66-19551c1cd944
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2020-12-16
Last Modified Date: 2020-12-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro documents a SideWinder APT campaign that targets government and military organizations in South Asia via spear-phishing and malicious documents (RTF, LNK, HTA, PDF, DOCX) that drop JavaScript droppers leading to a .NET backdoor/stealer; the campaign also hosts Android APKs (including Metasploit-based samples) on phishing servers and reuses topical lures (COVID‑19 and regional territorial disputes) to harvest credentials and exfiltrate data.
