Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SideWinder APT Hackers Attacking Indian Entities by Masquerading as the Income Tax Department of India

SideWinder APT Hackers Attacking Indian Entities by Masquerading as the Income Tax Department of India

Posted on December 22, 2025December 22, 2025 By CWS

The marketing campaign is run by the SideWinder superior persistent menace group and goals to plant a silent Home windows backdoor on sufferer machines.

As soon as energetic, the malware can steal information, seize knowledge and provides distant management to the attacker.

Every assault begins with a tax-themed e mail that urges the sufferer to evaluate an inspection doc.

The message features a surl.li hyperlink that results in a pretend tax portal at gfmqvip.vip, which copies the look of the true Revenue Tax website.

Phishing E mail Impersonating the Revenue Tax Division of India (Supply – Zscaler)

The portal then pushes an Inspection.zip file that’s saved on store10.gofile.io.

Zscaler analysts recognized this chain whereas looking for odd surl.li visitors inside massive Indian networks.

They noticed customers transfer from the brief hyperlink to the pretend tax web page, obtain Inspection.zip after which join out to recognized SideWinder servers.

Their work reveals how a easy trying tax e mail can result in long run entry inside delicate Indian programs. The downloaded Inspection.zip archive holds three key information and marks the beginning of the entire technical breakdown.

It accommodates a signed Microsoft Defender binary renamed as Inspection Doc Overview.exe however in reality SenseCE.exe, a malicious MpGear.dll library, and a decoy certificates file DMRootCA.crt.

Revenue Tax Division of India Phishing Web page (Supply – Zscaler)

When the person runs the “evaluate” program, Home windows masses MpGear.dll from the identical folder, a DLL facet‑loading trick that lets attacker code run inside a trusted course of.

Checks

Earlier than contacting the command server, MpGear.dll checks that the host is an actual goal and never a sandbox.

Sufferer Timezone Checks for Superior Geofencing (Supply – Zscaler)

It calls timeapi.io and worldtimeapi.org to learn the time zone and solely continues if the worth matches South Asia zones similar to UTC+5:30.

A typical config file can appear like this:-

C2=180.178.56.230

It additionally sleeps for about three and a half minutes to evade fast scans and appears at working processes earlier than loading the subsequent stage from the web.

Within the ultimate stage, MpGear.dll reaches out to eight.217.152.225 to fetch a small loader known as 1bin, drops a resident agent mysetup.exe within the C: folder, and writes a management file like YTSysConfig.ini that shops the command server 180.178.56.230 and different flags.

Observe us on Google Information, LinkedIn, and X to Get Extra On the spot Updates, Set CSN as a Most well-liked Supply in Google.

Cyber Security News Tags:APT, Attacking, Department, Entities, Hackers, Income, India, Indian, Masquerading, SideWinder, Tax

Post navigation

Previous Post: Rising Tides: When Cybersecurity Becomes Personal – Inside the Work of an OSINT Investigator
Next Post: Nissan Confirms Data Breach Following Unauthorized Access to Red Hat Servers

Related Posts

Operation ForumTrol Known for Exploiting Chrome 0-Day Attacking Users With New Phishing Campaign Operation ForumTrol Known for Exploiting Chrome 0-Day Attacking Users With New Phishing Campaign Cyber Security News
Ransomware Campaign Mimics Akira in South America Ransomware Campaign Mimics Akira in South America Cyber Security News
APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data Cyber Security News
Hackers Weaponize AWS X-Ray Service to Work as Covert Command & Control Server Hackers Weaponize AWS X-Ray Service to Work as Covert Command & Control Server Cyber Security News
Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life Cyber Security News
New Botnet Hijacks 9,000 ASUS Routers & Enables SSH Access by Injecting Public Key New Botnet Hijacks 9,000 ASUS Routers & Enables SSH Access by Injecting Public Key Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mythos Excels in Vulnerability Detection, Faces Varied Challenges
  • OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices
  • Revolutionizing Data Center Security with DPUs
  • Ghostwriter Intensifies Phishing Attacks on Ukraine
  • AI Enhances Security with Realistic Attack Simulations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mythos Excels in Vulnerability Detection, Faces Varied Challenges
  • OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices
  • Revolutionizing Data Center Security with DPUs
  • Ghostwriter Intensifies Phishing Attacks on Ukraine
  • AI Enhances Security with Realistic Attack Simulations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark