Sidewinder
Also reported as T-APT-04, Rattlesnake, SideWinder, APT-C-17, RAZOR TIGER and 6 other names. Linked to India by three sources.
Reports per quarter
Techniques seen in the last two years
- T1057 2 reports in ATT&CK
- T1105 2 reports in ATT&CK
- T1129 2 reports reports only
- T1218 2 reports reports only
- T1008 1 report reports only
- T1016 1 report in ATT&CK
- T1027 1 report reports only
- T1036 1 report reports only
- T1041 1 report reports only
- T1047 1 report reports only
Show all 30 techniques Show fewer
- T1056.001 1 report reports only
- T1059 1 report reports only
- T1071 1 report reports only
- T1071.001 1 report in ATT&CK
- T1082 1 report in ATT&CK
- T1095 1 report reports only
- T1106 1 report reports only
- T1112 1 report reports only
- T1185 1 report reports only
- T1204 1 report reports only
- T1204.002 1 report in ATT&CK
- T1489 1 report reports only
- T1497 1 report reports only
- T1547 1 report reports only
- T1547.001 1 report in ATT&CK
- T1566 1 report reports only
- T1566.001 1 report in ATT&CK
- T1573 1 report reports only
- T1574.001 1 report in ATT&CK
- T1620 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2010-3333 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-4792 KEV
- CVE-2013-3906 KEV
- CVE-2014-0224
- CVE-2014-1761 KEV
- CVE-2014-4114 KEV
- CVE-2014-6352 KEV
- CVE-2015-1427 KEV
- CVE-2015-1641 KEV
- CVE-2015-7645 KEV ransomware
Show all 46 CVEs Show fewer
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2016-8655
- CVE-2017-0199 KEV ransomware
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-3506 KEV
- CVE-2017-5689 KEV
- CVE-2017-8570 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-15982 KEV ransomware
- CVE-2018-4876
- CVE-2018-4878 KEV ransomware
- CVE-2018-4990 KEV
- CVE-2018-5002 KEV
- CVE-2018-7445 KEV
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2018-8453 KEV ransomware
- CVE-2018-8570
- CVE-2019-2215 KEV
- CVE-2019-5544 KEV ransomware
- CVE-2020-0674 KEV
- CVE-2020-0986 KEV
- CVE-2020-1380 KEV
- CVE-2020-3992 KEV ransomware
- CVE-2020-7961 KEV
- CVE-2021-1732 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-3007
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
Show all 84 reports Show fewer
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SideWinder Uses Server-side Polymorphism to Attack Pakistan Government Officials — and Is Now Targeting Turkey
-
AllaKore(d) the SideCopy Train
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor AllaKore(d) the SideCopy Train
-
The Sidewinder (APT-Q-39) uses Google Play to spread an analysis of malicious Android software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Sidewinder (APT-Q-39) uses Google Play to spread an analysis of malicious Android software
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SideWinder.AntiBot.Script Analysis of SideWinder's new infrastructure and tool that narrows their reach to Pakistan
-
APT_trends_report_Q2_2022_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2022_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 404 — File still found
-
State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage
-
VajraEleph from South Asia - Cyber espionage against Pakistani military personnel revealed
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor VajraEleph from South Asia - Cyber espionage against Pakistani military personnel revealed
-
What’s with the shared VBA code between Transparent Tribe and other threat actors-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What’s with the shared VBA code between Transparent Tribe and other threat actors-
-
ModifiedElephant APT and a Decade of Fabricating Evidence
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ModifiedElephant APT and a Decade of Fabricating Evidence
-
InSideCopy: How this APT continues to evolve its arsenal
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor InSideCopy: How this APT continues to evolve its arsenal
-
Cybersecurity_threats_2021-Q1-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cybersecurity_threats_2021-Q1-eng
-
Geopolitical nation-state threat actor overview May 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Geopolitical nation-state threat actor overview May 2021
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
APT SideWinder's latest attack on a certain region in South Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT SideWinder's latest attack on a certain region in South Asia
-
Renewed SideWinder Activity in South Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Renewed SideWinder Activity in South Asia
-
Malpedia Page for family Sidewinder
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malpedia Page for family Sidewinder
-
SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor SideWinder Uses South Asian Issues for Spear Phishing, Mobile Attacks
-
SideWinder Leverages South Asian Territorial Issues for Spear Phishing and Mobile Device Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SideWinder Leverages South Asian Territorial Issues for Spear Phishing and Mobile Device Attacks
-
APT_trends_report_Q3_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q3_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2020
-
SideWinder_APT_2020_H1_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor SideWinder_APT_2020_H1_CN_version
-
Copy cat of APT Sidewinder _. In tweeter this weekend,@Timele9527… _ by Sebdraven _ Medium
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Copy cat of APT Sidewinder _. In tweeter this weekend,@Timele9527… _ by Sebdraven _ Medium
-
Analysis of recent rattlesnake APT attacks against surrounding countries and regions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of recent rattlesnake APT attacks against surrounding countries and regions
-
Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FIN6 Compromised E-commerce Platform via Magecart to Inject Credit Card Skimmers Into Thousands of Online Shops
-
ShadowGate Returns to Worldwide Operations With Evolved Greenflash Sundown Exploit Kit
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowGate Returns to Worldwide Operations With Evolved Greenflash Sundown Exploit Kit
-
Outlaw Updates Kit to Kill Older Miner Versions, Targets More Systems
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Outlaw Updates Kit to Kill Older Miner Versions, Targets More Systems
-
First Active Attack Exploiting CVE-2019-2215 Found on Google Play, Linked to SideWinder APT Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor First Active Attack Exploiting CVE-2019-2215 Found on Google Play, Linked to SideWinder APT Group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor [CN]_SideWinder_APT
-
First Active Attack Exploiting CVE-2019-2215 Found on Google Play, Linked to SideWinder APT Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor First Active Attack Exploiting CVE-2019-2215 Found on Google Play, Linked to SideWinder APT Group
-
Magecart Skimming Attack Targets Mobile Users of Hotel Chain Booking Websites
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Magecart Skimming Attack Targets Mobile Users of Hotel Chain Booking Websites
-
Analyzing Digital Quartermasters in Asia – Do Chinese and Indian APTs Have a Shared Supply Chain?
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Digital Quartermasters in Asia – Do Chinese and Indian APTs Have a Shared Supply Chain?
-
2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
-
APT Sidewinder changes theirs TTPs to install their backdoor.
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Sidewinder changes theirs TTPs to install their backdoor.
-
Malicious document targets Vietnamese officials
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Malicious document targets Vietnamese officials
-
Malicious document targets Vietnamese officials – Sebdraven – Medium
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Malicious document targets Vietnamese officials – Sebdraven – Medium
-
Malicious document targets Vietnamese officials
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malicious document targets Vietnamese officials
-
APT Sidewinder- Tricks powershell, Anti Forensics and execution side loading
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Sidewinder- Tricks powershell, Anti Forensics and execution side loading
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 摩诃草组织
-
Sidewinder Targeted Attack Against Android In The Golden Age Of Ad Libraries
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sidewinder Targeted Attack Against Android In The Golden Age Of Ad Libraries
Newest first. Details opens the report in Explore.