Categories: Cyber Security News

Nepal Unrest Exploited – Sidewinder APT Deploys Cross-Platform Malware on Windows and Mobile Devices

The Sidewinder APT group has shifted its focus to exploit ongoing political unrest in Nepal, deploying sophisticated cross-platform malware campaigns targeting users interested in the country’s current protests and government instability.

Following their previously documented attacks against South Asian military targets, the threat actors are now leveraging Nepal’s social media ban and anti-corruption demonstrations as social engineering lures to deliver multi-stage attacks across Windows and Android platforms.

Impersonating High-Profile Nepali Officials

The campaign demonstrates tactical evolution as attackers impersonate General Ashok Sigdel, Nepal’s current Army Chief of Staff, who has been serving as the acting head of state since September 2025.

Acting head of nepal

The malicious operation begins with credential phishing sites spoofing the Nepalese Emergency Service, designed to harvest login credentials from unsuspecting victims.

Users attempting to access information about General Sigdel are instead tricked into downloading Gen_Ashok_Sigdel_Live.apk, a malicious Android application that functions as a sophisticated data exfiltration tool.

Ida-esque view of the android malware

The Android malware, based on a modified version of the open-source Rafel RAT, requests extensive device permissions, including. ADD_DEVICE_ADMINREAD_EXTERNAL_STORAGEMANAGE_APP_ALL_FILES_ACCESS_PERMISSIONREAD_CONTACTS, and READ_MEDIA_VIDEO.

Once installed, the malware displays decoy content while simultaneously harvesting documents and images from the infected device, uploading stolen data to command-and-control servers at playservicess.com.

Multi-Platform Attack Infrastructure

Sidewinder’s campaign extends beyond mobile devices to include Windows-based attacks using EmergencyApp.exe additional Android samples like Emergency_Help.apk.

A fake site purporting to be the “emergency helpline”

The threat actors maintain consistent infrastructure across platforms, utilizing domains  playservicess.com and playsevices.com hosted on an IP address 194.233.77.73.

Network communications utilize distinctive markers, including the boundary string “qwerty” and URI paths containing “/ghijkl/ghijkl/index.php”, providing defenders with reliable hunting signatures.

The group’s previous campaigns targeted military personnel across Bangladesh, Pakistan, and India using similar tactics, with evidence suggesting victims included defense contractors, government officials, and military communications personnel based on recovered contact lists and stolen SMS content.

Their infrastructure demonstrates sophisticated operational security, with domains registered using consistent email patterns and C2 panels that were temporarily indexed by search engines before being secured.

The current Nepal-focused campaign represents a concerning adaptation of established TTPs to exploit real-world geopolitical events, highlighting the group’s continued focus on South Asian targets while expanding its operational scope to capitalize on emerging political instability and social unrest.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post Nepal Unrest Exploited – Sidewinder APT Deploys Cross-Platform Malware on Windows and Mobile Devices appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Nashville tourism zone bill moves through Tennessee Legislature

A new, state-controlled board could provide tax bailouts to downtown Nashville bars to aid them…

1 minute ago

Bills requiring Tennessee sheriffs to cooperate with ICE advance

A state Senate bill requires Tennessee sheriffs to hold inmates sought by immigration agents for…

2 minutes ago

Tennessee House fails to protect national treasure in Big South Fork National River

Big South Fork River in Scott County is a nation park and draws tourists to…

2 minutes ago

Avatar: The Last Airbender Movie Animator Comments on Leak

An animator on The Legend of Aang: The Last Airbender has hit out at the…

56 minutes ago

PlayStation Plus Games Lineup Leaks

Sony's PlayStation Plus games lineup for May 2026 has leaked online, led by Horizon Zero…

56 minutes ago

Daredevil Actor Gives Avengers: Doomsday Update

As speculation mounts that Daredevil star Charlie Cox may appear again on the big screen,…

57 minutes ago

This website uses cookies.