mail-kpt-gov-pk[.]shazad-gids[.]workers[.]dev is not an address belonging to the Karachi Port Trust, but it is built to be mistaken for one. According to a threat advisory published by the security firm Rewterz, it is one of seven lookalike domains the espionage group SideWinder is using against Pakistani government and defence organisations.
The other named targets are the National Radio and Telecommunication Corporation and Pakistan Ordnance Factories, the state owned arms manufacturer. Two further domains spoof Pakistani government mail hosts. Three more sit on a different host, fetchdrives[.]info, dressed as finance ministry addresses.
A fourteen year old operation with a fresh list
SideWinder, also tracked as Rattlesnake, has been active since at least 2012 and is believed to be based in India. Its usual targets are government, military, diplomatic and financial organisations across South Asia and the Middle East, and its usual goal is intelligence rather than money. Rewterz describes the same working method here: spear phishing and social engineering to get a document opened, then code inside that document to get a foothold. Pakistan has been in that crosshair for years, and not only from Indian-linked operators. We covered an Iranian campaign against Turkish and Pakistani organisations that leaned on a similar document lure.
A Word file that phones home
The lures are .doc files carrying VBA macro downloaders. A macro is code stored inside the document itself, which runs if the recipient enables it. The advisory says those downloaders open command and control communication and pull down remote access trojans, after which the group uses custom malware and backdoors to stay resident, survey the network and take data out. Rewterz does not name the malware families involved, and publishes no sample hashes to pin them to.
Seven domains worth blocking today
The indicators below are defanged. Re-arm them only in a controlled environment.
- mail-kpt-gov-pk[.]shazad-gids[.]workers[.]dev
- email-nrtc-com-pk-auth[.]shazad-gids[.]workers[.]dev
- mail-dgdp-gov[.]pk-uploads[.]workers[.]dev
- mail-dgmp-gov[.]pk-uploads[.]workers[.]dev
- finance-gov-pk[.]fetchdrives[.]info
- www-finance-gov-pk[.]fetchdrives[.]info
- pk[.]fetchdrives[.]info
Block the domains, then go looking
Rewterz's guidance is unglamorous and correct. Block the indicators at the perimeter, then search existing mail gateway and DNS logs for them rather than treating a new block rule as a clean bill of health: the advisory does not say when these domains were first seen, so a block today does not rule out earlier contact. Disable Office macros from the internet by policy where you can, and treat any unsolicited mail claiming to come from a ministry or a port authority as suspect until it is verified through a channel you already trust. The full advisory, including its longer remediation list, is available from Rewterz.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.