Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SideWinder Targets Government Emails with Fake PDF Viewer

SideWinder Targets Government Emails with Fake PDF Viewer

Posted on April 21, 2026 By CWS

A sophisticated cyber threat group known as SideWinder has initiated a targeted phishing operation against government entities in South Asia. This campaign employs a deceptive Chrome PDF viewer and an exact replica of the Zimbra email login interface to illegally obtain employee login details.

Phishing Campaign Details

Active since February 2026, this malicious effort has focused on significant institutions such as the Bangladesh Navy and Pakistan’s Ministry of Foreign Affairs, among others. The attack strategy begins when a victim clicks on a spearphishing link, leading them to a page mimicking Google Chrome’s native PDF viewer.

The phishing tool, named Z2FA_LTS, uses PDF.js version 2.16.105 to create a realistic fake viewer, complete with standard toolbar functionalities. The document shown is an actual, but unreadable, diplomatic cable from Pakistan concerning the 152nd IPU Assembly in Istanbul. The page automatically redirects after a short delay, advancing the attack sequence.

Mechanisms of the Attack

Research by Breakglass Intelligence uncovered the phishing toolkit after a Cloudflare Workers URL hosting a Zimbra credential stealing script was identified. This script was specifically targeting Bangladesh Navy’s mail portal, mail.navy.mil.bd. Subsequent analysis revealed seven distinct phishing tools across two Cloudflare accounts targeting various organizations.

Several researchers, including @Huntio and @malwrhunterteam, verified the attribution to SideWinder. A critical operational security error by the developers exposed a full system path, uncovering the username “moincox” and the internal project code “Z2FA_LTS,” suggesting the existence of multiple versions of this phishing tool.

Preventive Measures and Recommendations

The Z2FA_LTS phishing kit is strategically crafted to deceive users at every step. After encountering the blurred PDF, victims face a fake Zimbra loading screen that closely resembles the genuine Bangladesh Navy email server. The login page further tricks users into re-entering credentials, collecting sensitive information.

Security teams are advised to take immediate action. The Bangladesh Navy should update all mail.navy.mil.bd passwords, and notify BGD e-GOV CIRT at [email protected]. Additionally, Pakistan’s NTISB should be informed of the leaked diplomatic data. Cloudflare should be alerted about malicious Workers subdomains, and organizations are encouraged to monitor for similar patterns of attacks.

Continuous vigilance and proactive measures are crucial in combating such sophisticated cyber threats. Stay informed by following us on Google News, LinkedIn, and X for more updates.

Cyber Security News Tags:Bangladesh Navy, Cloudflare, credential theft, Cybersecurity, digital threats, email security, Express.js, government security, IT security, Pakistan Ministry, PDF viewer, Phishing, SideWinder, South Asia, Zimbra

Post navigation

Previous Post: GitHub AI Agents Exposed to New Vulnerability
Next Post: North Korean Group Implicated in $290M Kelp DAO Crypto Theft

Related Posts

FBI Warns of Ploutus Malware Draining ATMs Nationwide FBI Warns of Ploutus Malware Draining ATMs Nationwide Cyber Security News
FancyBear Security Breach Uncovers NATO Espionage Efforts FancyBear Security Breach Uncovers NATO Espionage Efforts Cyber Security News
Huge Surge in Fake Investment Platforms Mimic Forex Exchanges Steal Logins Huge Surge in Fake Investment Platforms Mimic Forex Exchanges Steal Logins Cyber Security News
Threat Actors Leverage Google Apps Script To Host Phishing Websites Threat Actors Leverage Google Apps Script To Host Phishing Websites Cyber Security News
Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition Cyber Security News
New Open-Source Tool From Microsoft to Analyze Malware Hidden Within Rust Binaries New Open-Source Tool From Microsoft to Analyze Malware Hidden Within Rust Binaries Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark