CSIDB logo
Incident

Sri Lankan Ministry of Defense

Incident posture

Attack window
Dec 2020
Location
Sri Lanka
Status
Historical
CIA posture
Available to members
Updated
2025-12-09 00:00

Linked entities

Victim
Sri Lankan Ministry of Defense
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Dec 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The SideWinder advanced persistent threat group conducted a cyber espionage campaign targeting military and government entities in Nepal and Afghanistan using phishing emails with regional territorial dispute lures. The attackers deployed credential-harvesting techniques, emailed backdoors, and malicious mobile applications to compromise systems and steal sensitive information. This operation aimed to gather intelligence from high-value targets through coordinated social engineering and malware distribution.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The SideWinder APT group targeted government and military units in South Asia, including the Sri Lankan Ministry of Defense, using sophisticated phishing and malware techniques. They created convincing fake webmail login pages to harvest credentials and installed a backdoor to exfiltrate sensitive information. The attackers exploited the CVE-2017-11882 vulnerability in Microsoft Office to run malicious code, which collected system information and uploaded it to a command-and-control server. The campaign also included the development of mobile apps designed to gather private data, although some were still under development. The attack compromised both confidentiality and integrity, with no evidence of disruption to system availability.

Sources

Sources available to members: 1 source.

CSIDB