Researchers traced a SideWinder spearphishing campaign to a malicious Word document named "Briefing on Ongoing Projects.docx" that fetched a remote RTF template from a spoofed domain and exploited Microsoft Equation Editor via CVE-2017-11882. The recovered RTF decrypted embedded JavaScript, launched an obfuscated script, and executed a .NET component that profiled installed antivirus products before attempting to download a further payload stage. Investigators found the originally malicious RTF had later been replaced with a nearly empty placeholder file, a tactic that obscured follow-on analysis while preserving infrastructure clues.
Additional infrastructure and tradecraft links tied the activity to broader South Asian espionage patterns involving malicious RTF lures, Equation Editor exploitation, and multi-stage loaders. Fortinet separately documented a spearphishing attack against a telecommunications agency in South Asia using an RTF lure that exploited CVE-2018-0798, abused Logitech DLL search order hijacking with a signed executable and malicious LBTServ.dll, injected into svchost.exe, and contacted instructor[.]giize[.]com to retrieve a payload linked through OSINT to PoisonIvy RAT. Across the references, the campaigns show consistent use of document-based initial access, obfuscated intermediate stages, and reusable infrastructure and tooling associated with long-running regional espionage operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
DCSO CyTec published analysis of the SideWinder lure document "Briefing on Ongoing Projects.docx," tracing its remote RTF template, Equation Editor exploitation, JavaScript stage, and obfuscated .NET component. The researchers concluded the original malicious RTF had likely been replaced on the server with a placeholder file and linked related infrastructure through a shared path pattern.
FortiGuard published analysis connecting the South Asia telecom attack to the longer-running PivNoxy and Chinoxy threat cluster. The report also linked the actor's tooling and Logitech DLL hijacking tradecraft to Operation NightScout and earlier activity dating back to 2016.
The RTF sample researchers treated as the likely original malicious template for the SideWinder chain was first submitted to VirusTotal. The file exploited Microsoft Equation Editor and led to JavaScript and .NET payload stages.
A February 2022 tweet by ShadowChasing1 initially identified the malicious Word document "Briefing on Ongoing Projects.docx" as related to SideWinder. This is the earliest explicit public identification of the lure noted in the sources.
FortiGuard found a related LBTServ.dll sample submitted to VirusTotal from France in January 2022. It was tied to a campaign that used a signed Logitech executable to sideload malware, and FortiGuard assessed it was likely by the same actor as the South Asia telecom intrusion.
A nearly empty RTF file later assessed to be a placeholder replacement for a malicious template was first uploaded to VirusTotal. Researchers linked this file to the SideWinder infection chain via the same remote template URL path.
A telecommunications agency in South Asia was targeted with a spearphishing email disguised as coming from a Pakistan government division. The attached Royal Road-crafted RTF exploited CVE-2018-0798 and launched a Logitech DLL sideloading chain associated with the PivNoxy/Chinoxy cluster.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcefortinet.com
Open sourcevirustotal.com
Open sourcevirustotal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.