Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SideWinder Targets Government Emails with Fake PDF Viewer

SideWinder Targets Government Emails with Fake PDF Viewer

Posted on April 21, 2026 By CWS

A sophisticated cyber threat group known as SideWinder has initiated a targeted phishing operation against government entities in South Asia. This campaign employs a deceptive Chrome PDF viewer and an exact replica of the Zimbra email login interface to illegally obtain employee login details.

Phishing Campaign Details

Active since February 2026, this malicious effort has focused on significant institutions such as the Bangladesh Navy and Pakistan’s Ministry of Foreign Affairs, among others. The attack strategy begins when a victim clicks on a spearphishing link, leading them to a page mimicking Google Chrome’s native PDF viewer.

The phishing tool, named Z2FA_LTS, uses PDF.js version 2.16.105 to create a realistic fake viewer, complete with standard toolbar functionalities. The document shown is an actual, but unreadable, diplomatic cable from Pakistan concerning the 152nd IPU Assembly in Istanbul. The page automatically redirects after a short delay, advancing the attack sequence.

Mechanisms of the Attack

Research by Breakglass Intelligence uncovered the phishing toolkit after a Cloudflare Workers URL hosting a Zimbra credential stealing script was identified. This script was specifically targeting Bangladesh Navy’s mail portal, mail.navy.mil.bd. Subsequent analysis revealed seven distinct phishing tools across two Cloudflare accounts targeting various organizations.

Several researchers, including @Huntio and @malwrhunterteam, verified the attribution to SideWinder. A critical operational security error by the developers exposed a full system path, uncovering the username “moincox” and the internal project code “Z2FA_LTS,” suggesting the existence of multiple versions of this phishing tool.

Preventive Measures and Recommendations

The Z2FA_LTS phishing kit is strategically crafted to deceive users at every step. After encountering the blurred PDF, victims face a fake Zimbra loading screen that closely resembles the genuine Bangladesh Navy email server. The login page further tricks users into re-entering credentials, collecting sensitive information.

Security teams are advised to take immediate action. The Bangladesh Navy should update all mail.navy.mil.bd passwords, and notify BGD e-GOV CIRT at [email protected]. Additionally, Pakistan’s NTISB should be informed of the leaked diplomatic data. Cloudflare should be alerted about malicious Workers subdomains, and organizations are encouraged to monitor for similar patterns of attacks.

Continuous vigilance and proactive measures are crucial in combating such sophisticated cyber threats. Stay informed by following us on Google News, LinkedIn, and X for more updates.

Cyber Security News Tags:Bangladesh Navy, Cloudflare, credential theft, Cybersecurity, digital threats, email security, Express.js, government security, IT security, Pakistan Ministry, PDF viewer, Phishing, SideWinder, South Asia, Zimbra

Post navigation

Previous Post: GitHub AI Agents Exposed to New Vulnerability
Next Post: North Korean Group Implicated in $290M Kelp DAO Crypto Theft

Related Posts

Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network Cyber Security News
Malicious Rust Evm-Units Mimic as EVM Version Silently Executes OS-specific Payloads Malicious Rust Evm-Units Mimic as EVM Version Silently Executes OS-specific Payloads Cyber Security News
Lumma Infostealers Developers Trying Hard To Conduct Business As Usual Lumma Infostealers Developers Trying Hard To Conduct Business As Usual Cyber Security News
Critical FortiSIEM Vulnerability Let Attackers to Execute Malicious Commands Critical FortiSIEM Vulnerability Let Attackers to Execute Malicious Commands Cyber Security News
Google Enhances Ad Security with Gemini AI Google Enhances Ad Security with Gemini AI Cyber Security News
Microsoft Announces New Security Defaults for Windows 365 Cloud PCs Microsoft Announces New Security Defaults for Windows 365 Cloud PCs Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Critical Vulnerabilities in Cisco and Kentico
  • Understanding Identity-Based Cyber Attacks and Defense
  • North Korean Group Implicated in $290M Kelp DAO Crypto Theft
  • SideWinder Targets Government Emails with Fake PDF Viewer
  • GitHub AI Agents Exposed to New Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Critical Vulnerabilities in Cisco and Kentico
  • Understanding Identity-Based Cyber Attacks and Defense
  • North Korean Group Implicated in $290M Kelp DAO Crypto Theft
  • SideWinder Targets Government Emails with Fake PDF Viewer
  • GitHub AI Agents Exposed to New Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark