Close Menu
Computing.net
    Facebook X (Twitter) Instagram
    Computing.netComputing.net
    • News
      1. AI
      2. Crypto
      3. Gaming
      4. Hardware
      5. Security
      6. Software
      7. View All

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      AI Trading Bot Loses $441K in Crypto After Decimal Point Mistake

      February 23, 2026

      Tesla (TSLA) Stock: Goodbye Sedans, Hello Robots in Dramatic Production Shift

      January 29, 2026

      Palantir Technologies (PLTR) Stock: Why Bears May Be Wrong About Valuation Concerns

      January 29, 2026

      SUI Token Rallies 40% Following Major Staking Event and CME Futures Announcement

      May 12, 2026

      Chainlink (LINK) Surges to $10.40 as Network Activity Hits Eight-Month Peak

      May 12, 2026

      Dogecoin Whales Ramp Up Accumulation as DOGE Eyes Critical Breakout Levels

      May 12, 2026

      Bitcoin Holds $81K While Burry Flags Nasdaq Bubble and Oil Surges Past $105

      May 12, 2026

      Hamster Kombat: Unraveling TON’s Gaming Phenomenon

      August 7, 2024

      W-Coin: Exploring the Latest Telegram Tap-to-Earn Phenomenon

      August 7, 2024

      Hamster Kombat: 300 Million Players & Counting, HMSTR Token Airdrop Soon!

      July 31, 2024

      Hamster Kombat Developers Work with TON Team on Airdrop Solution

      July 30, 2024

      Nothing Expands Product Line with New AI Feature & Phone Update

      July 31, 2024

      Security Audit Reveals Concerns in Atari’s Blockchain Game on Base

      August 6, 2024

      SideWinder Group Targets Maritime Facilities in New Cyber Espionage Campaign

      July 30, 2024

      OAuth Implementation Flaw Exposes Millions of Websites to XSS Attacks

      July 30, 2024

      Hamster Kombat Players Face Growing Cybersecurity Threats

      July 25, 2024

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      Cookie Crumble: Google Halts Plans to Eliminate Third-Party Cookies in Chrome

      July 23, 2024

      Big Brother is Watching: Apple’s Creepy New Ad Urges iPhone Users to Ditch Chrome

      July 23, 2024

      Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

      May 12, 2026

      Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

      May 12, 2026

      GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

      May 12, 2026

      SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

      May 12, 2026
    • How To

      Batch Files: Tokens and Delimiters (FOR Loops)

      July 31, 2024

      Types of Ethernet Cabling & Electrical Low Voltage Wiring

      July 9, 2024

      What You Should Know About .JSON File Extension

      January 10, 2023

      Bkup File Extension

      November 19, 2022

      HEIC File Extension

      November 19, 2022
    • Office
      1. Excel
      2. Google Sheets
      3. View All

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024

      How to Remove Characters from Right in Excel

      July 30, 2023

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      Bullet Points in Google Sheets

      January 20, 2022

      Sort by Date in Google Sheets

      January 18, 2022

      Google Sheets Timestamp

      January 17, 2022

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024
    • Answers
    • About
    • Contact
    Facebook X (Twitter)
    Computing.net
    Security

    SideWinder Group Targets Maritime Facilities in New Cyber Espionage Campaign

    A cyber espionage campaign attributed to the SideWinder group is targeting maritime facilities in multiple countries using spear-phishing emails and old Microsoft Office vulnerabilities.
    Oliver DaleBy Oliver DaleJuly 30, 2024
    Twitter LinkedIn Email Telegram
    Twitter LinkedIn Email Telegram

    TLDR

    • SideWinder, a nation-state threat actor believed to be affiliated with India, is conducting a new cyber espionage campaign.
    • The campaign targets ports and maritime facilities in countries around the Indian Ocean and Mediterranean Sea.
    • Attackers use spear-phishing emails with malicious Microsoft Word documents as the initial attack vector.
    • The attack exploits old vulnerabilities in Microsoft Office (CVE-2017-0199 and CVE-2017-11882) to deliver malware.
    • Targeted countries include Pakistan, Egypt, Sri Lanka, Bangladesh, Myanmar, Nepal, and the Maldives.

    A new cyber espionage campaign targeting maritime facilities in multiple countries has been uncovered by security researchers. The campaign, attributed to a group known as SideWinder, is believed to be affiliated with India and has been active since 2012.

    The BlackBerry Research and Intelligence Team discovered that SideWinder is targeting ports and maritime facilities in countries around the Indian Ocean and Mediterranean Sea. The affected countries include Pakistan, Egypt, Sri Lanka, Bangladesh, Myanmar, Nepal, and the Maldives.

    SideWinder, also known by other names such as APT-C-17 and Razor Tiger, uses spear-phishing emails as its main attack method. These emails contain malicious Microsoft Word documents designed to trick recipients into opening them. The attackers use emotionally charged topics like sexual harassment, employee termination, and salary cuts to increase the chances of victims opening the attachments.

    When a victim opens the malicious document, it exploits an old security flaw (CVE-2017-0199) in Microsoft Office. This vulnerability, which was patched in 2017, allows the document to connect to a malicious website controlled by the attackers. The website is disguised to look like it belongs to Pakistan’s Directorate General Ports and Shipping.

    The attack then proceeds to download another malicious file that exploits another old vulnerability (CVE-2017-11882) in the Microsoft Office Equation Editor. This leads to the execution of malicious code on the victim’s computer.

    The attackers have taken steps to avoid detection. Their malware checks if it’s running on a real computer or in a virtual environment used by security researchers. If it determines the system is of interest, it proceeds to download and run additional malicious code.

    While the exact nature of the final payload isn’t known, researchers believe the goal is likely intelligence gathering. This fits with SideWinder’s previous campaigns, which have focused on espionage.

    The use of old vulnerabilities in this campaign highlights the importance of keeping software up to date. Many organizations still use older versions of Microsoft Office, which makes them vulnerable to these kinds of attacks.

    To protect against such threats, security experts recommend several measures:

    1. Keep all software, especially Microsoft Office, updated with the latest security patches.
    2. Train employees to recognize and report phishing attempts.
    3. Use advanced email filtering solutions to block malicious emails.
    4. Implement real-time threat detection and response systems.

    The maritime industry, which plays a crucial role in global trade, appears to be a particular target in this campaign. This could be due to the strategic importance of shipping and port facilities to national economies and security.

    Share. Twitter LinkedIn Email Telegram
    Oliver Dale
    • Website
    • X (Twitter)
    • LinkedIn

    Editor-in-Chief of Computing.net and founder of Kooc Media, A UK-Based Online Media Company. Believer in Open-Source Software, Blockchain Technology & a Free and Fair Internet for all. His writing has been quoted by Nasdaq, Dow Jones, Investopedia, The New Yorker, Forbes, Techcrunch & More. Contact Oliver@blockonomi.com

    Related Posts

    Security Audit Reveals Concerns in Atari’s Blockchain Game on Base

    August 6, 2024

    OAuth Implementation Flaw Exposes Millions of Websites to XSS Attacks

    July 30, 2024

    Hamster Kombat Players Face Growing Cybersecurity Threats

    July 25, 2024

    UK Police Arrest 17-Year-Old Suspect in MGM Resorts Cyberattack Investigation

    July 23, 2024

    Spanish Authorities Arrest Pro-Russian Hackers Targeting Ukraine’s Allies

    July 23, 2024

    Lawmakers Demand Answers: CrowdStrike CEO Called to Testify on Global Tech Outage

    July 23, 2024
    Add A Comment

    Comments are closed.

    Latest

    Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

    May 12, 2026

    Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

    May 12, 2026

    GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

    May 12, 2026

    SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

    May 12, 2026

    Trump Dismisses Iran Peace Proposal — Oil Markets React as Hormuz Remains Restricted

    May 12, 2026
    • Facebook
    • Twitter

    Latest Reviews

    Meta Platforms Shares Tumble 8% Despite Strong Q1 Performance Amid AI Investment Surge

    April 30, 2026

    Flush.com Review: Casino & Sportsbook With 275% Welcome Bonus

    March 7, 2026

    Katsubet Review: Crypto Casino With 300% Welcome Bonus & Free Spins

    March 7, 2026

    7Bit Review: Crypto Casino With 325% Bonus & 250 FS

    March 7, 2026

    Mega Dice Review: Crypto Casino With 200% Bonus & 50 Free Spins, Legit?

    March 7, 2026


    Home / Privacy Policy / Terms & Conditions

    Computing.net © 1996 - 2026 Kooc Media Ltd. All rights reserved. Registered Company No.05695741

    Type above and press Enter to search. Press Esc to cancel.