Territory disputes between India and its neighbours are targets for malware campaigns

The group’s target include multiple government and military units, primarily in Nepal and Afghanistan, researchers at Trend Micro, a cybersecurity firm, said in a report.

Updated - December 11, 2020 08:24 pm IST

Published - December 11, 2020 05:41 pm IST

A representative image of a hacker.

A representative image of a hacker.

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

The recent territory disputes between India, China, Pakistan and Nepal came in handy for a cybercrime group SideWinder. It launched phishing and malware attacks using territory dispute themes to lure users.

The group’s target include multiple government and military units, primarily in Nepal and Afghanistan, researchers at Trend Micro, a cybersecurity firm, said in a report.

They found a server used to deliver malicious LNK file and host multiple credential phishing pages, which were copied from victims’ webmail login pages and modified for phishing.

After the gathered credentials are sent, some of the phishing pages redirect victims to different documents or news pages with themes related to COVID-19 or territory disputes between India and neighbouring countries.

SideWinder group has become famous for targeting countries in the South Asian region. The group had previously launched attacks against Pakistan, Bangladesh, and China using lure files related to COVID-19.

Trend Micro collected different samples from the campaign and found that all cases either downloaded or dropped files, and then executed JavaScript code to install the main backdoor + stealer.

“Although it’s not clear to us how these phishing pages are delivered to the victims, finding the original webmail servers that they copied to make these phishing pages allows us to identify who they were targeting,” researchers noted.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.