Researchers reported that SideWinder ran a five-month credential-harvesting campaign against South Asian military, government, telecommunications, and defense-sector organizations by abusing legitimate PaaS infrastructure instead of traditional attacker-controlled hosting. The operation used about 20 infrastructure nodes across Zeabur, Leapcell, Railway, Cloudflare Workers, Replit, Back4App, and URL shorteners including short.gy and tinyurl.cx, with many phishing assets hosted on free-tier subdomains that could be quickly rebuilt after takedowns. Breakglass Intelligence linked the activity with high confidence to SideWinder based on targeting, Zimbra-themed phishing tradecraft, lure themes, and overlap with prior operations.
The campaign targeted entities in Pakistan and Bangladesh, including Margalla Heavy Industries Limited, Bangladesh Navy, Pakistan Air Force, Nayatel, Bangladesh Computer Council, NTC Pakistan, and an unidentified international relations organization. Investigators said the attackers used a five-stage phishing chain with cloned Zimbra login pages that stole the same victim’s password twice, and they decoded a victim address, pgcoord-251@margallahil[.]com, from a phishing URL tied to Margalla Heavy Industries. A reused query parameter appeared across all phishing URLs for five months, giving defenders a potential detection signature, while two Zeabur-hosted phishing sites remained active and harvesting credentials at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
As of 2026-04-05, researchers reported that two Zeabur-hosted phishing sites tied to the campaign were still live and actively harvesting credentials. This showed the infrastructure remained operational despite the broader investigation into the campaign.
By April 2026, Breakglass Intelligence assessed with high confidence that the activity was conducted by SideWinder based on targeting patterns, Zimbra credential-phishing tradecraft, lure themes, and overlap with previously reported SideWinder operations. The researchers described the campaign as part of the group's broader 2026 activity across diplomacy, civilian government, military, defense industry, and telecommunications in at least four countries.
During the campaign, SideWinder used a multi-stage Zimbra-themed phishing flow that harvested the same victim's password twice through separate credential pages impersonating organizations such as Bangladesh Navy and Pakistan Air Force. Researchers also found a reused query parameter across all phishing URLs for five months, which they assessed as a strong detection signature.
In November 2025, a URLScan capture revealed a phishing URL containing a base64-decoded email address for a project coordinator at Margalla Heavy Industries Limited, linking the campaign to a confirmed Pakistani defense-sector victim. Breakglass later identified the address as pgcoord-251@margallahil[.]com.
Between November 2025 and April 2026, researchers observed SideWinder running a credential-harvesting campaign against military, government, telecom, and defense-sector organizations in Pakistan and Bangladesh using legitimate PaaS infrastructure and URL shorteners. The operation ultimately spanned 20 infrastructure nodes across providers including Zeabur, Leapcell, Railway, Cloudflare Workers, Replit, Back4App, short.gy, and tinyurl.cx.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.