Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SideWinder APT Hackers Attacking Indian Entities by Masquerading as the Income Tax Department of India

SideWinder APT Hackers Attacking Indian Entities by Masquerading as the Income Tax Department of India

Posted on December 22, 2025December 22, 2025 By CWS

The marketing campaign is run by the SideWinder superior persistent menace group and goals to plant a silent Home windows backdoor on sufferer machines.

As soon as energetic, the malware can steal information, seize knowledge and provides distant management to the attacker.

Every assault begins with a tax-themed e mail that urges the sufferer to evaluate an inspection doc.

The message features a surl.li hyperlink that results in a pretend tax portal at gfmqvip.vip, which copies the look of the true Revenue Tax website.

Phishing E mail Impersonating the Revenue Tax Division of India (Supply – Zscaler)

The portal then pushes an Inspection.zip file that’s saved on store10.gofile.io.

Zscaler analysts recognized this chain whereas looking for odd surl.li visitors inside massive Indian networks.

They noticed customers transfer from the brief hyperlink to the pretend tax web page, obtain Inspection.zip after which join out to recognized SideWinder servers.

Their work reveals how a easy trying tax e mail can result in long run entry inside delicate Indian programs. The downloaded Inspection.zip archive holds three key information and marks the beginning of the entire technical breakdown.

It accommodates a signed Microsoft Defender binary renamed as Inspection Doc Overview.exe however in reality SenseCE.exe, a malicious MpGear.dll library, and a decoy certificates file DMRootCA.crt.

Revenue Tax Division of India Phishing Web page (Supply – Zscaler)

When the person runs the “evaluate” program, Home windows masses MpGear.dll from the identical folder, a DLL facet‑loading trick that lets attacker code run inside a trusted course of.

Checks

Earlier than contacting the command server, MpGear.dll checks that the host is an actual goal and never a sandbox.

Sufferer Timezone Checks for Superior Geofencing (Supply – Zscaler)

It calls timeapi.io and worldtimeapi.org to learn the time zone and solely continues if the worth matches South Asia zones similar to UTC+5:30.

A typical config file can appear like this:-

C2=180.178.56.230

It additionally sleeps for about three and a half minutes to evade fast scans and appears at working processes earlier than loading the subsequent stage from the web.

Within the ultimate stage, MpGear.dll reaches out to eight.217.152.225 to fetch a small loader known as 1bin, drops a resident agent mysetup.exe within the C: folder, and writes a management file like YTSysConfig.ini that shops the command server 180.178.56.230 and different flags.

Observe us on Google Information, LinkedIn, and X to Get Extra On the spot Updates, Set CSN as a Most well-liked Supply in Google.

Cyber Security News Tags:APT, Attacking, Department, Entities, Hackers, Income, India, Indian, Masquerading, SideWinder, Tax

Post navigation

Previous Post: Rising Tides: When Cybersecurity Becomes Personal – Inside the Work of an OSINT Investigator
Next Post: Nissan Confirms Data Breach Following Unauthorized Access to Red Hat Servers

Related Posts

AI Tools Like GPT Direct Users to Phishing Sites Instead of Legitimate Ones AI Tools Like GPT Direct Users to Phishing Sites Instead of Legitimate Ones Cyber Security News
Top 10 Best Supply Chain Risk Management Solutions in 2025 Top 10 Best Supply Chain Risk Management Solutions in 2025 Cyber Security News
Urgent Updates for Jenkins Plugins Fix Critical Flaws Urgent Updates for Jenkins Plugins Fix Critical Flaws Cyber Security News
PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution Cyber Security News
Silver Fox Shifts Tactics to Python-Based Threats in Asia Silver Fox Shifts Tactics to Python-Based Threats in Asia Cyber Security News
Threat Actors Allegedly Listed Windows Zero-Day RCE Exploit For Sale on Dark Web Threat Actors Allegedly Listed Windows Zero-Day RCE Exploit For Sale on Dark Web Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark