◇ SIGN IN
← all actors
apt

Bahamut

activemedium confidence
APT / State-sponsored
WindshiftBahamutAPT-C-58
Attribution
Cyber-mercenary / hack-for-hire espionage group; sponsor unconfirmed. MITRE consolidates Bahamut and Windshift under one entry (G0112); some vendors treat them as distinct but related clusters.
Origin
Unknown
First seen
2017
Last active
2024
Motivation
Espionage
Confidence
medium
MENA targeting
Egypt, Iran, Palestine, Turkey, Tunisia, Saudi Arabia, Qatar, UAE
Sectors
Government officials, diplomats, human rights NGOs, activists
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Egypt, Iran, Palestine (Government officials, diplomats, human rights NGOs sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Bahamut is a highly capable, likely mercenary espionage actor known for prolific Android and iOS spyware, elaborate fake-persona infrastructure and disinformation, operating across the Middle East and South Asia.

History

Bahamut was named by BlackBerry/Bellingcat and has been active since at least 2017. MITRE tracks the related Windshift activity as G0112, folding 'Bahamut' in as an alias, though several vendors describe Bahamut and Windshift as overlapping-but-separate clusters targeting individuals for surveillance across the Middle East and critical infrastructure.

The group is distinguished by unusually polished operational security and social engineering: bespoke phishing sites, fake news outlets and elaborate personas support delivery of custom mobile spyware. On Android it repackages legitimate VPN, chat and utility apps (e.g., Trojanized SoftVPN/OpenVPN via fake SecureVPN sites, and the 'SafeChat' lure), while historically also fielding iOS profiles and Windows components.

Capabilities focus on exfiltrating messages from WhatsApp, Signal, Telegram, Viber and Messenger, plus documents, photos, location and credentials. ESET documented sustained fake-VPN Android campaigns (2022 onward); other reporting tied SafeChat-style lures to South Asian, particularly Indian, targets.

MENA relevance: Bahamut/Windshift has repeatedly surveilled individuals in Gulf and broader Middle Eastern government and critical-infrastructure contexts, alongside South Asian targeting. Confidence in the activity is high; attribution to any specific state or contracting sponsor is low and remains an open question, consistent with a hack-for-hire model.

Notable campaigns

2018-2019
Windshift surveillance (WindTail)
Targeted surveillance of Gulf government and critical-infrastructure individuals using macOS WindTail and mobile implants.
2022
Fake SecureVPN Android campaign
ESET documented Trojanized SoftVPN/OpenVPN apps delivered via a fake VPN site to steal victims' messaging data.
2023
SafeChat
A fake Android chat app used to exfiltrate data from targets, with a focus on individuals in South Asia/India.

Observed ATT&CK techniques · 8

TechniqueNameTacticObserved use
T1665Hide Infrastructuredefense evasionBAHAMUT's operational security is notable for having no domain or IP address cross-over between operational functions -- no domains or IP addresses used to control or distribute Windows malware are reused for phishing or for administering malware for any other operating system.
T1036Masqueradingdefense evasionMalicious mobile apps were disguised as legitimate VPN applications (e.g., trojanized SoftVPN/OpenVPN) complete with convincing supporting web presence to appear legitimate to app-store reviewers and users.
T1204.002User Execution: Malicious FileexecutionGroup relies on malware only as a last resort but is highly adept at phishing, tending to aim for mobile phones of specific individuals as a way into an organization, requiring the target to install/open the malicious application.
T1203Exploitation for Client ExecutionexecutionUse of zero-day exploits was identified among the group's Windows malware samples, reflecting a skill level beyond most other known threat-actor groups; specific CVEs were not named in the source.
T1566Phishinginitial accessBAHAMUT is behind a number of extremely targeted and elaborate phishing and credential-harvesting campaigns against government officials and private-sector VIPs in the Middle East and South Asia; the group typically uses spearphishing messages as an initial attack vector.
T1195.002Supply Chain Compromise: Compromise Software Software Supply Chain (trojanized VPN apps)initial accessFake applications -- trojanized versions of legitimate VPN apps such as SoftVPN and OpenVPN, repackaged with Bahamut spyware code -- were used as an initial attack vector; nine malicious iOS apps were found in the Apple App Store and an assortment of Android apps directly attributable to BAHAMUT via unique fingerprints, complete with well-designed websites, privacy policies, and terms of service to bypass Google/Apple store safeguards.
T1598Phishing for InformationreconnaissanceThe group runs extremely targeted and elaborate credential-harvesting campaigns as part of its phishing operations.
T1583.001Acquire Infrastructure: Domainsresource developmentThe group maintains segmented, non-overlapping domain and IP infrastructure across its Windows malware, phishing, and mobile-malware operations as part of its distinct operational tradecraft.