SideWinder-Associated Campaign Targeting South Asian Government and Financial Infrastructure

Published on 17-Sep-2026 15:00:00

Executive Summary

BGD e-GOV CIRT Cyber Threat Intelligence Unit is issuing this advisory regarding a newly reported suspected SideWinder-associated operational infrastructure targeting organizations across South Asia, including government-related infrastructure in Bangladesh.

On 15 September 2026, researchers identified an exposed VPS at 66.179.31[.]191, hosted on AS399629, that exposed a Python SimpleHTTP directory on TCP/8898. The directory reportedly contained approximately 395 files across nine subdirectories totaling approximately 182 MB. The recovered material included vulnerability-exploitation scripts, credential-testing tools, session cookies, target lists, C2 configurations, payload-related artifacts and operational logs.

The recovered toolkit included exploitation capability against GeoServer/GeoTools, Laravel Ignition, Apache Tomcat Manager and Redis, as well as weak-credential testing against phpMyAdmin. The infrastructure also contained Sliver and Vshell, an out-of-band callback service and reverse-shell tooling. Operational logs reportedly showed active scanning, exploitation activity and interactive shell access.

The research identified Bangladesh government infrastructure within recovered target lists and, more significantly, several Bangladesh government-related phpMyAdmin endpoints in a credential-testing script. However, presence in a target list or credential-testing list must not be interpreted as confirmed compromise. The researchers explicitly distinguish broad reconnaissance from the smaller set of systems for which active exploitation evidence was recovered.

The tooling, infrastructure and victimology reportedly overlap with publicly documented

SideWinder tradecraft. Nevertheless, the available evidence does not conclusively establish

attribution to SideWinder or a state sponsor. BGD e-GOV CIRT therefore recommends treating

the activity as a high-priority threat-hunting lead rather than as confirmed attribution.

Full advisory is below: