Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SideWinder Targets Government Emails with Fake PDF Viewer

SideWinder Targets Government Emails with Fake PDF Viewer

Posted on April 21, 2026 By CWS

A sophisticated cyber threat group known as SideWinder has initiated a targeted phishing operation against government entities in South Asia. This campaign employs a deceptive Chrome PDF viewer and an exact replica of the Zimbra email login interface to illegally obtain employee login details.

Phishing Campaign Details

Active since February 2026, this malicious effort has focused on significant institutions such as the Bangladesh Navy and Pakistan’s Ministry of Foreign Affairs, among others. The attack strategy begins when a victim clicks on a spearphishing link, leading them to a page mimicking Google Chrome’s native PDF viewer.

The phishing tool, named Z2FA_LTS, uses PDF.js version 2.16.105 to create a realistic fake viewer, complete with standard toolbar functionalities. The document shown is an actual, but unreadable, diplomatic cable from Pakistan concerning the 152nd IPU Assembly in Istanbul. The page automatically redirects after a short delay, advancing the attack sequence.

Mechanisms of the Attack

Research by Breakglass Intelligence uncovered the phishing toolkit after a Cloudflare Workers URL hosting a Zimbra credential stealing script was identified. This script was specifically targeting Bangladesh Navy’s mail portal, mail.navy.mil.bd. Subsequent analysis revealed seven distinct phishing tools across two Cloudflare accounts targeting various organizations.

Several researchers, including @Huntio and @malwrhunterteam, verified the attribution to SideWinder. A critical operational security error by the developers exposed a full system path, uncovering the username “moincox” and the internal project code “Z2FA_LTS,” suggesting the existence of multiple versions of this phishing tool.

Preventive Measures and Recommendations

The Z2FA_LTS phishing kit is strategically crafted to deceive users at every step. After encountering the blurred PDF, victims face a fake Zimbra loading screen that closely resembles the genuine Bangladesh Navy email server. The login page further tricks users into re-entering credentials, collecting sensitive information.

Security teams are advised to take immediate action. The Bangladesh Navy should update all mail.navy.mil.bd passwords, and notify BGD e-GOV CIRT at [email protected]. Additionally, Pakistan’s NTISB should be informed of the leaked diplomatic data. Cloudflare should be alerted about malicious Workers subdomains, and organizations are encouraged to monitor for similar patterns of attacks.

Continuous vigilance and proactive measures are crucial in combating such sophisticated cyber threats. Stay informed by following us on Google News, LinkedIn, and X for more updates.

Cyber Security News Tags:Bangladesh Navy, Cloudflare, credential theft, Cybersecurity, digital threats, email security, Express.js, government security, IT security, Pakistan Ministry, PDF viewer, Phishing, SideWinder, South Asia, Zimbra

Post navigation

Previous Post: GitHub AI Agents Exposed to New Vulnerability
Next Post: North Korean Group Implicated in $290M Kelp DAO Crypto Theft

Related Posts

HubSpot’s Jinjava Engine Vulnerability Exposes Thousands of Websites to RCE Attacks HubSpot’s Jinjava Engine Vulnerability Exposes Thousands of Websites to RCE Attacks Cyber Security News
IRGC Hacker Groups Attacking Targeted Financial, Government, and Media Organizations IRGC Hacker Groups Attacking Targeted Financial, Government, and Media Organizations Cyber Security News
BadIIS Malware Exploits IIS Servers for Illicit Redirects BadIIS Malware Exploits IIS Servers for Illicit Redirects Cyber Security News
Microsoft Teams Call Weaponized to Deploy and Execute Matanbuchus Ransomware Microsoft Teams Call Weaponized to Deploy and Execute Matanbuchus Ransomware Cyber Security News
2,000+ Devices Hacked Using Weaponized Social Security Statement Themes 2,000+ Devices Hacked Using Weaponized Social Security Statement Themes Cyber Security News
Zero-Day Exploits Hit Microsoft Edge, Windows 11, and LiteLLM Zero-Day Exploits Hit Microsoft Edge, Windows 11, and LiteLLM Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic’s Claude Services Experience Major Disruption
  • New Gafgyt Variant C0XMO Targets Linux Systems
  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic’s Claude Services Experience Major Disruption
  • New Gafgyt Variant C0XMO Targets Linux Systems
  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark