Observed activity associated with Sidewinder APT. Lure document: No.9374.docx, 64f2681ad0940e6c2c9c76e6834117bf. Observed C2 infrastructure: update[.]ms-office[.]app

Pulse ID: 6a3cbe4f68f14d09a3331ef4
Pulse Link: https://otx.alienvault.com/pulse/6a3cbe4f68f14d09a3331ef4
Pulse Author: Tr1sa111
Created: 2026-06-25 05:36:15

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #InfoSec #OTX #Office #OpenThreatExchange #Sidewinder #bot #Tr1sa111

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Observed activity associated with Sidewinder APT. Lure document: No.9374.docx, 64f2681ad0940e6c2c9c76e6834117bf. Observed C2 infrastructure: update[.]ms-office[.]app

Recent activity has been detected linked to the Sidewinder advanced persistent threat group. The campaign utilizes a malicious document named No.9374.docx with the hash value 64f2681ad0940e6c2c9c76e6834117bf as a lure mechanism. The infrastructure supporting command and control operations includes the domain update[.]ms-office[.]app. This observation indicates ongoing operations by Sidewinder, a threat actor known for targeting specific regions and sectors. The use of weaponized documents and deceptive domains mimicking legitimate Microsoft services demonstrates continued sophisticated social engineering tactics employed by this group.

Pulse ID: 6a3b4e5dc7cef5136c49c364
Pulse Link: https://otx.alienvault.com/pulse/6a3b4e5dc7cef5136c49c364
Pulse Author: AlienVault
Created: 2026-06-24 03:26:21

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #ICS #InfoSec #MaliciousDocument #Microsoft #Mimic #OTX #Office #OpenThreatExchange #RAT #Sidewinder #SocialEngineering #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
United States Navy F-16C VFC-13 "Fighting Saints" brings the heat in the R-2508 Sidewinder Low Level Complex, May 29th, 2026 #f16 #F16C #VFC13 #R2508 #milair #fightingSaints #nikon #aviationphotography #photography #Sidewinder #AvGeek #cvvhrn #lowlevel #afterburner
USAF F-16D 90-0848 of the 416th Flight Test Squadron "Skulls" running the R-2508 Sidewinder Low Level Complex, May 28th 2026 #F16C #USAF #aggressor #Sidewinder #EdwardsAFB #Skulls #milair #planespotting #AvGeek #spotter #photography #Nikon #cvvhrn #R2508 #lowlevel #lowleveljets
USAF F-16C 89-2048 "Wraith" 64th Aggressor Squadron "Gomers", Nellis AFB running the R-2508 Sidewinder Low Level Complex, May 28th 2026 #F16C #USAF #aggressor #Sidewinder #NellisAFB #milair #Wraith #planespotting #AvGeek #spotter #photography #Nikon #cvvhrn #R2508 #lowlevel #lowleveljets
USN F/A-18E VFA-146 “Blue Diamonds”, CVW-17 (USS Nimitz CVN-68) and NAS Lemoore running the running the R-2508 Sidewinder Low Level Complex, May 29th 2026 #Sidewinder #NellisAFB #milair #planespotting #AvGeek #spotter #photography #Nikon #cvvhrn #R2508 #lowlevel #lowleveljets #VFA146
USAF F-16C 64th Aggressor Squadron "Gomers", Nellis AFB running the R-2508 Sidewinder Low Level Complex, June 2025 #F16C #USAF #aggressor #Sidewinder #NellisAFB #milair #aviationphotography #planespotting #AvGeek #spotter #photography #Nikon #cvvhrn #nikonphotography #R2508 #lowlevel #lowleveljets
USAF F-16C 89-2048 "Wraith" 64th Aggressor Squadron "Gomers", Nellis AFB running the R-2508 Sidewinder Low Level Complex, May 28th 2026 #F16C #USAF #aggressor #Sidewinder #NellisAFB #milair #Wraith #planespotting #AvGeek #spotter #photography #Nikon #cvvhrn #R2508 #lowlevel #lowleveljets
USN F/A-18F 166635 of VX-31 "Dust Devils" NAWS China Lake running R-2508 Sidewinder Low Level Complex, June 2, 2026 #Sidewinder #ChinaLake #VX31 #DustDevils #FA18 #AvGeek #photography #Nikon #cvvhrn #R2508 #lowlevel #lowleveljets
United States Navy F-16C VFC-13 "Fighting Saints" brings the heat in the R-2508 Sidewinder Low Level Complex, Today May 28th, 2026 #f16 #F16C #VFC13 #R2508 #milair #fightingSaints #nikon#aviationphotography #photography #Sidewinder #AvGeek #cvvhrn #lowlevel #afterburner