Alpha Cyber

Beyond the Inbox: Mapping SideWinder’s Stealthy C2 Infrastructure

The Threat:The Sidewinder APT group, believed to be aligned with Indian interests, is actively targeting government, military, and critical infrastructure across South Asia, including Bangladesh, Pakistan, and Sri Lanka.

Alpha Cyber Research1 min readupdated 1 Apr 2026
SideWinder C2 Graph

Sidewinder Indian APT Hackers: Mapping the “advisory.army-govbd.info” Botnet C2 Infrastructure

The Threat:
The Sidewinder APT group, believed to be aligned with Indian interests, is actively targeting government, military, and critical infrastructure across South Asia, including Bangladesh, Pakistan, and Sri Lanka. Their latest campaigns leverage sophisticated spear-phishing techniques, weaponized documents, and a robust command-and-control (C2) infrastructure, one notable C2 domain being advisory.army-govbd.info.

How Sidewinder’s C2 Infrastructure Operates


Phishing & Document Exploitation: Sidewinder initiates attacks using emails with malicious attachments exploiting vulnerabilities like CVE-2017-0199. These weaponized documents often mimic official government communications to lure victims.

C2 Domains: Once a victim opens the malicious file, their device connects to attacker-controlled domains such as advisory.army-govbd.info. These C2 servers issue commands, exfiltrate data, and deploy additional malware modules.

Stealth and Evasion: The group uses server-side polymorphism, obfuscated code, and geofencing to avoid detection and ensure only targeted victims are affected.

Using VirusTotal to Map the Infrastructure
Security professionals leverage VirusTotal to identify and map Sidewinder’s infrastructure:

Search for C2 domains and related indicators (like advisory.army-govbd.info) to uncover associated IPs, URLs, and malicious files.

Track infrastructure overlap: VirusTotal’s correlation features help link new domains and document hashes to ongoing Sidewinder campaigns, revealing the broader botnet and attack ecosystem.

Why Your Organization Should Care


Targeted Sectors: Sidewinder is known to focus on government, military, logistics, telecom, and financial organizations in South Asia.

Advanced Tactics: Their use of ever-changing infrastructure and tailored phishing makes traditional defenses less effective.

Potential Impact: Successful breaches can lead to espionage, data theft, and operational disruption.

How We Can Help


Our cybersecurity services can:

Monitor and block malicious domains like advisory.army-govbd.info using real-time threat intelligence.

Detect spear-phishing and document-based attacks before they reach your users.

Continuously map and track APT infrastructure using advanced tools like VirusTotal, ensuring your defenses adapt as threats evolve.

Stay ahead of sophisticated threats. Contact us to secure your organization against APT groups like Sidewinder.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]