Alpha Cyber

Exposing the Indian SideWinder Hacker Group: Targeting Users with Fake Outlook/Zimbra

Blocking Critical IP and Domain IOCs In the world of cyber threats, attribution is key to understanding and mitigating attacks.

Alpha Cyber Research3 min readupdated 1 Apr 2026
SideWinder Hacker Group

In the world of cyber threats, attribution is key to understanding and mitigating attacks. The Indian SideWinder Hacker Group, a highly sophisticated threat actor, has been targeting users with fake Outlook/Zimbra instances to gain unauthorized access to sensitive information. This type of social engineering attack is just one aspect of their multi-layered, stealthy approach to infiltrating networks.

Through infrastructure mapping techniques, security experts have identified key indicators of compromise (IOCs) associated with this group, allowing organizations to proactively defend against future attacks.

This blog post focuses on exposing the critical IP addresses and domains linked to the SideWinder group and providing you with an IOC table to block these malicious resources. By using this mapping, businesses can better protect their users and infrastructure from these dangerous threat actors.

Understanding the Threat:

SideWinder Hacker Group Targets Users with Fake Outlook-Zimbra IP Graph

The Indian SideWinder Hacker Group has been active for several years, with a history of targeting government institutions and private organizations across the globe. They are known to deploy fake email systems, including Outlook and Zimbra, to trick users into entering their login credentials, which are then harvested for further malicious use.

To make these attacks even more credible, the group uses spoofed IP addresses and domain names to hide their true identity. This makes it difficult for traditional security measures to identify and block them effectively.

By understanding the infrastructure used by these attackers, you can strengthen your security posture and block the domains and IP addresses they rely on.

Critical IOCs Linked to SideWinder Hacker Group:

The table below lists key IOCs that have been identified in connection with the SideWinder group’s infrastructure. These indicators can be used to help organizations proactively block malicious traffic and prevent unauthorized access to their systems.

Indicator TypeIOC (Indicator of Compromise)Description
IP Address46.183.184.245Associated with SideWinder operations, used in phishing and social engineering attacks.
Domaingovmm[.]orgLinked to the fake Outlook/Zimbra instances deployed by SideWinder.
Domaingovnp[.]orgAnother malicious domain used by the group for similar attack vectors.
Domainandc[.]govaf[.]orgFrequently used in targeted spear-phishing campaigns against government sectors.
Hostnamefmaildd.000webhostapp.comLinked to phishing websites mimicking email login pages.
Hostnamemtatdd.000webhostapp.comAnother malicious site used for fake email services, often used in phishing campaigns.
Hostnamenmailddt.000webhostapp.comUtilized for fake email login pages, a common tactic by SideWinder.

How You Can Protect Your Organization:

1. Implement Network Monitoring:
By integrating threat intelligence feeds and monitoring for these IOCs, you can detect malicious activity in real time. Look for traffic from these IP addresses or attempts to connect to these domains, which can be early warning signs of an attack.

2. Block Malicious IPs and Domains:
Use firewalls, web proxies, or DNS filtering tools to block these specific IP addresses and domains associated with the SideWinder group. This is a critical step in preventing unauthorized access and phishing attacks.

3. Educate Employees on Phishing Risks:
Train users to recognize phishing attempts, particularly those involving fake login pages for Outlook or Zimbra. Make sure your employees understand how to spot fake emails and avoid clicking on suspicious links.

4. Use Multi-Factor Authentication (MFA):
Even if an attacker manages to compromise a login credential, MFA can act as an additional layer of protection. This prevents attackers from accessing sensitive systems even with valid credentials.

5. Conduct Regular Security Audits:
Continuously assess your organization’s security posture through audits and penetration testing to identify potential vulnerabilities that could be exploited by groups like SideWinder.

Conclusion:

By mapping out the infrastructure used by the Indian SideWinder Hacker Group, we can better understand their tactics and proactively defend against their attacks. The IOCs listed in the table are just a starting point by blocking these malicious indicators and implementing a comprehensive security strategy, you can significantly reduce the risk of falling victim to this advanced threat actor.

Stay ahead of cybercriminals. Protect your systems, your data, and your employees by taking proactive steps today. For more information on how we can assist you in securing your network and preventing future attacks, contact us now.

Your Business, Our Priority. Protecting Against the Evolving Cyber Threats.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]