No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

SideWinder Strikes Victims in Pakistan, Turkey in Multiphase Polymorphic Attack

May 9, 2023
in Protection
0
SideWinder Strikes Victims in Pakistan, Turkey in Multiphase Polymorphic Attack



India’s prolific SideWinder advanced persistent threat group (APT) is targeting Pakistani government officials and individuals in Turkey, using polymorphism techniques that allow it to bypass traditional signature-based antivirus (AV) detection to deliver a next-stage payload.

The attacks use documents with content geared toward their interests, which when opened exploit a remote template injection flaw to deliver malicious payloads, the researchers at the BlackBerry Threat Research and Intelligence team revealed in a blog post on May 8.

The first phase of the campaign — discovered in November — uses a server-side polymorphic attack against targets in Pakistan, while a later phase discovered earlier this year uses phishing tactics to deliver malicious lure documents to victims, the researchers said.  

However, instead of using malicious macros within documents to drop malware — which is often the case when documents are used as lures — the APT exploits the CVE-2017-0199 vulnerability to deliver the payloads instead, the researchers said.

SideWinder, active since 2012, was detected by Kaspersky in the first quarter of 2018 and thought to primarily target Pakistani military infrastructure. However, as recent research and the latest attack demonstrate, the target range of the group — widely believed to be associated with Indian espionage interests — appears to be far broader than that.

How Polymorphism Tricks Defenders

Server-side polymorphism is a technique used since the 1990s by attackers to evade detection by AV tools. It does so by using malicious code that alters its appearance through encryption and obfuscation, making sure that no two samples look the same and thus can’t easily be analyzed, the researchers explained.

The attack can fool defenders because it serves the victim with a new sample each time a link is clicked, Dmitry Bestuzhev, senior director of cyber-threat intelligence at BlackBerry, tells Dark Reading. In this case, each new download has a new hash, which “effectively breaks hash-based detections used by security operations centers (SOCs) and some endpoint scanners,” he says.

“Since there’s a new hash each time, there is no information on a given sample on public multi scanners like VirusTotal unless each new sample is uploaded over and over for further analysis,” Bestuzhev says. “So it makes life harder for the victims because of the lack of information on public sandboxes and other-like security services.”

The Latest Campaign

BlackBerry researchers examined various documents in the campaign, which were found on an attacker-controlled server used to deliver the documents to users. The first that researchers encountered was titled “GUIDELINES FOR BEACON JOURNAL – 2023 PAKISTAN NAVY WAR COLLEGE (PNWC),” while another discovered in early December pretended to be a letter of offer and acceptance “for the purchase of defense articles, defense services, or both.”

In both cases, targets were instructed to reach out to remote addresses controlled by SideWinder that would download the next-stage payload, “file.rtf,” a rich text document file that demonstrates the polymorphic nature of the attack and can only be downloaded by users in the Pakistani IP range, the researchers said.

“The name of the file ‘file.rtf’ and the file type are the same; however, the contents, file size and the file hash are different,” they noted. “This is an example of server-based polymorphism, where each time the server responds with a different version of file, so bypassing the victim’s antivirus scanner (presuming the antivirus uses signature-based detection).”

If the user is not in the Pakistani IP range, the server returns an 8 byte RTF file that contains a single string; however, if the user is within the Pakistani IP range, the server then returns the RTF payload, which varies between 406KB to 414KB in size, the researchers said.

To Turkey & Beyond: An Expanding Cyber Threat

In early March, the researchers discovered a new malicious document linked to the earlier attack that was propagated via phishing emails, indicating that the scope of the attack had spread to victims in Turkey — a new target region for SideWinder, researchers said. In mid-March, the researchers discovered a newly configured server delivering the payload that was set up so that a victim in Turkey could receive a second-stage payload, they said.

While SideWinder’s primary targets have always been the Southeast Asia regions such as Pakistan and Sri Lanka, with a particular focus on Pakistani government institutions. However, targeting victims in Turkey makes sense from a geopolitical perspective, the researchers observed, because of the Turkish government’s support of Pakistan, which has sparked criticism from India, they said.

While polymorphic attacks overall can be difficult to defend against, detection and prevention strategies based on behavior and hashes can be effectively used against them, Bestuzhev says.

“When prevention technologies are based on code similarities and heuristics or machine learning models, even if there is a new hash, it should not break the detection of the malicious sample,” he notes.

The key for organizations to mitigate these attacks, Bestuzhev adds, “is not to focus on volatile indicators of compromise but on meaningful tactics, techniques, and procedures (TTPs) and behaviors in the system or code blocks covered by machine learning technologies.”

Editorial Team

Editorial Team

Related Posts

Galaxy Enhance-X Is Samsung's Best Photo and Video Editing Tool
Protection

Galaxy Enhance-X Is Samsung’s Best Photo and Video Editing Tool

April 22, 2026
The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘A Knight of the Seven Kingdoms'
Protection

The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘A Knight of the Seven Kingdoms’

April 22, 2026
How to Spot AI Audiobooks on Libby
Protection

How to Spot AI Audiobooks on Libby

April 21, 2026
The Best Last-Minute Deals From Home Depot's 'Spring Black Friday' Sale
Protection

The Best Last-Minute Deals From Home Depot’s ‘Spring Black Friday’ Sale

April 21, 2026
10 Hacks Every Apple CarPlay User Should Know
Protection

10 Hacks Every Apple CarPlay User Should Know

April 21, 2026
The Samsung Galaxy Watch Ultra Is Over $100 Off Right Now
Protection

The Samsung Galaxy Watch Ultra Is Over $100 Off Right Now

April 21, 2026
Load More
Next Post
Plug Power Stock Drops as Hydrogen Prices Hit Results

Plug Power Stock Drops as Hydrogen Prices Hit Results

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Chainalysis: Crypto Money Laundering Surged to $82 Billion in 2025

    0 shares
    Share 0 Tweet 0
  • Trump extends sanctions exemption on Russian oil shipments already at sea

    0 shares
    Share 0 Tweet 0
  • XRP Funding Rates Stay Negative On Binance Throughout 2026 — What This Means

    0 shares
    Share 0 Tweet 0
  • Explainer-How the State of the Union became a stage for political confrontation

    0 shares
    Share 0 Tweet 0

Latest News

Boeing’s defense business is booming at a time when airplanes are disappointing

Boeing’s defense business is booming at a time when airplanes are disappointing

April 22, 2026
0

Boeing’s stock jumped Wednesday, as a partnership with the Trump administration on PAC-3 interceptor missiles provided a boost to the...

Career Program Advisor - HigherEdJobs

Career Program Advisor – HigherEdJobs

April 22, 2026
0

DESCRIPTION:Develops and implements efficient and effective student recruitment, retention, and completion initiatives for career and technical education (AS, CCERT and...

Folk2Folk appoints Joanna Chan as head of strategic capital

Folk2Folk appoints head of strategic capital

April 22, 2026
0

Folk2Folk has appointed Joanna Chan as head of strategic capital to strengthen its focus on institutional funding. In the newly-created...

Galaxy Enhance-X Is Samsung's Best Photo and Video Editing Tool

Galaxy Enhance-X Is Samsung’s Best Photo and Video Editing Tool

April 22, 2026
0

Samsung's One UI software for its Galaxy phones comes packed with features and functionality, but there are also several official...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.