← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Z2FA_LTS: A Sidewinder APT Phishing Kit Developer Burns Their Linux Username in an Express.js Stack Trace.
The Z2FA_LTS phishing kit represents a sophisticated cyber threat associated with the Sidewinder APT, targeting governmental entities in South Asia, including the Bangladesh Navy and Pakistan's Ministry of Foreign Affairs. The phishing operation leverages a polished Zimbra webmail clone, designed to harvest user credentials through a highly deceptive interface. The kit's architecture includes server-rendered pages using Express.js, deploying on Cloudflare Workers, which has proven effective for evading detection.
MITRE ATT&CK & Malware Families
Indicators of Compromise (3 / 6 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| URL | http://mail.navy.mil.bd | — | 2026-04-26 | |
| URL | https://mail.navy.mil.bd/ | — | 2026-04-26 | |
| URL | https://mail.navy.mil.bd/css/common | — | 2026-04-26 |