CSIDB logo
Incident

Presidential Palace

Incident posture

Attack window
Dec 2020
Location
Afghanistan
Status
Historical
CIA posture
Available to members
Updated
2025-12-09 00:00

Linked entities

Victim
Presidential Palace
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Dec 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The SideWinder advanced persistent threat group conducted a cyberespionage campaign targeting government and military entities in Afghanistan, employing phishing emails designed to steal credentials and deliver backdoors. Attackers leveraged geopolitical tensions involving regional territorial disputes as lures to compromise victims, deploying malicious mobile applications alongside email-based attacks to facilitate intelligence gathering. The operation aimed to exfiltrate sensitive information from high-value targets, including Afghanistan's Presidential Palace, through coordinated multi-platform intrusion techniques.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The SideWinder advanced persistent threat (APT) group conducted a cyberespionage campaign targeting government and military entities in Afghanistan and Nepal around December 2020. Attackers employed phishing emails containing malicious links designed to steal email credentials, using territorial disputes between China, India, Nepal, and Pakistan as thematic lures to increase credibility. Successful compromises led to the deployment of backdoors on infected systems, enabling persistent network access. The group simultaneously distributed malicious mobile applications to expand surveillance capabilities across devices. Security researchers identified the campaign as part of SideWinder's ongoing intelligence-gathering operations against South Asian targets, with Afghan government institutions representing primary objectives.

The operation aimed to exfiltrate sensitive information from compromised networks, potentially affecting national security assets and diplomatic communications. Analysis revealed the campaign's alignment with SideWinder's established tactics, including multi-platform targeting and geopolitical-themed social engineering. No specific data breaches or mitigation measures by affected organizations were publicly documented in available sources. Cybersecurity firms detected and analyzed the campaign, attributing it to SideWinder based on technical indicators and historical activity patterns. The incident demonstrated continued APT interest in regional geopolitical intelligence through cyber means during periods of heightened interstate tensions.

Sources

Sources available to members: 1 source.

CSIDB