← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Z2FA_LTS: A Sidewinder APT Phishing Kit Developer Burns Their Linux Username in an Express.js Stack Trace.
The Z2FA_LTS phishing kit represents a sophisticated cyber threat associated with the Sidewinder APT, targeting governmental entities in South Asia, including the Bangladesh Navy and Pakistan's Ministry of Foreign Affairs. The phishing operation leverages a polished Zimbra webmail clone, designed to harvest user credentials through a highly deceptive interface. The kit's architecture includes server-rendered pages using Express.js, deploying on Cloudflare Workers, which has proven effective for evading detection.
MITRE ATT&CK & Malware Families
Indicators of Compromise (1 / 6 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | e41adf9fdd1394e1d6ee74efd05a7c6a | — | 2026-04-26 |