PULSE NAME
Evasive SideWinder APT Campaign Detected
WHITE RAZOR TIGER AlienVault 2025-12-20 Modified: 2026-01-19
32
IOCs
MEDIUM VOLUME
A sophisticated espionage campaign targeting Indian entities has been identified, masquerading as the Income Tax Department of India. The activity is associated with the SideWinder APT group, which has evolved its toolkit to evade detection by mimicking Chinese enterprise software. The campaign uses DLL side-loading techniques with legitimate Microsoft Defender binaries to bypass EDR, and utilizes public cloud storage and URL shorteners to evade reputation-based detections. The threat actors employ geofencing behavior, focusing on systems in South Asian timezones. The attack chain includes phishing emails, fraudulent websites, and malicious payloads delivered through file-sharing services. The final stage involves a resident agent that beacons to a command-and-control server, mimicking Chinese endpoint tool protocols.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
MpGear.dll mysetup.exe
Indicators of Compromise (32)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 537abad75fc343690119851610d9b54b 2025-12-20
FileHash-MD5 6a3b5fed4383a2e54d70b4a01c44ba01 2025-12-20
FileHash-MD5 7f397f286905114b94da3ec9052cb89d 2025-12-20
FileHash-MD5 eb5bd49b6eef60ff85892ef7c8015b01 2025-12-20
FileHash-SHA1 27c009dd858214be785455ea97b42b4103309331 2025-12-20
FileHash-SHA1 8d61f9c6205c30f4e88ced1076dc79acb2ec2b69 2025-12-20
FileHash-SHA1 a5f381bd3e08b0e91c61382c7de8ae78f7d69a6e 2025-12-20
FileHash-SHA256 13474f4e82b8fa13c6e43009433720e07e0485971293afdc5867849b9fac8f09 2025-12-20
FileHash-SHA256 415be77f99144c27e2612e1021043f61302b28e28fa3262b1792c1e4a9d668d4 2025-12-20
FileHash-SHA256 950ad7a33457a1a37a0797316cdd2fbaf9850f7165425274351d08b3c01ed2d8 2025-12-20
domain gfmqvip.vip 2025-12-20
domain gofjasj.help 2025-12-20
domain googleaxc.shop 2025-12-20
domain googlehkcom.com 2025-12-20
domain googlevip.icu 2025-12-20
domain googlevip.shop 2025-12-20
domain googlewery.cyou 2025-12-20
domain googlewww.qpon 2025-12-20
domain gsrydkjz.cyou 2025-12-20
domain hetyqraftryt.cyou 2025-12-20
domain mrysaqw.qpon 2025-12-20
domain oopae.icu 2025-12-20
domain oopv.shop 2025-12-20
domain oytdwzz.shop 2025-12-20
domain qqooe.click 2025-12-20
domain sow4.shop 2025-12-20
domain stockjp.top 2025-12-20
domain wgooglegoogle.com 2025-12-20
domain wwsxcpl.shop 2025-12-20
domain wwwqqo.icu 2025-12-20
domain zhantugaokao.com 2025-12-20
domain zibenbang.vip 2025-12-20