Cyber-mercenary / hack-for-hire espionage group; sponsor unconfirmed. MITRE consolidates Bahamut and Windshift under one entry (G0112); some vendors treat them as distinct but related clusters.
Origin
Unknown
First seen
2017
Last active
2024
Motivation
Espionage
Attribution confidence
medium
MENA targeting
Egypt, Iran, Palestine, Turkey, Tunisia, Saudi Arabia, Qatar, UAE
Sectors
Government officials, diplomats, human rights NGOs, activists
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Egypt, Iran, Palestine (Government officials, diplomats, human rights NGOs sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
BAHAMUT's operational security is notable for having no domain or IP address cross-over between operational functions -- no domains or IP addresses used to control or distribute Windows malware are reused for phishing or for administering malware for any other operating system.
[Windshift](https://attack.mitre.org/groups/G0112) has used malware to identify installed AV and commonly used forensic and malware analysis tools.(Citation: BlackBerry Bahamut)
Use of zero-day exploits was identified among the group's Windows malware samples, reflecting a skill level beyond most other known threat-actor groups; specific CVEs were not named in the source.
[Windshift](https://attack.mitre.org/groups/G0112) has used e-mail attachments to lure victims into executing malicious code.(Citation: SANS Windshift August 2018)
[Windshift](https://attack.mitre.org/groups/G0112) has used links embedded in e-mails to lure victims into executing malicious code.(Citation: SANS Windshift August 2018)
[Windshift](https://attack.mitre.org/groups/G0112) has sent spearphishing emails with attachment to harvest credentials and deliver malware.(Citation: SANS Windshift August 2018)
[Windshift](https://attack.mitre.org/groups/G0112) has used compromised websites to register custom URL schemes on a remote system.(Citation: objective-see windtail1 dec 2018)
[Windshift](https://attack.mitre.org/groups/G0112) has used fake personas on social media to engage and target victims.(Citation: SANS Windshift August 2018)
[Windshift](https://attack.mitre.org/groups/G0112) has sent spearphishing emails with links to harvest credentials and deliver malware.(Citation: SANS Windshift August 2018)
BAHAMUT is behind a number of extremely targeted and elaborate phishing and credential-harvesting campaigns against government officials and private-sector VIPs in the Middle East and South Asia; the group typically uses spearphishing messages as an initial attack vector.
Fake applications -- trojanized versions of legitimate VPN apps such as SoftVPN and OpenVPN, repackaged with Bahamut spyware code -- were used as an initial attack vector; nine malicious iOS apps were found in the Apple App Store and an assortment of Android apps directly attributable to BAHAMUT via unique fingerprints, complete with well-designed websites, privacy policies, and terms of service to bypass Google/Apple store safeguards.
The group maintains segmented, non-overlapping domain and IP infrastructure across its Windows malware, phishing, and mobile-malware operations as part of its distinct operational tradecraft.
[Windshift](https://attack.mitre.org/groups/G0112) has used revoked certificates to sign malware.(Citation: objective-see windtail1 dec 2018)(Citation: SANS Windshift August 2018)
[Windshift](https://attack.mitre.org/groups/G0112) has used icons mimicking MS Office files to mask malicious executables.(Citation: objective-see windtail1 dec 2018) [Windshift](https://attack.mitre.org/groups/G0112) has also attempted to hide executables by changing the file extension to ".scr" to
Associated software
1 linked · 1 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 1
Sourced from MITRE ATT&CK's own uses relationships for this group.
Regional co-occurrence is association, not prediction. These techniques appeared alongside Bahamut's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Adaptive Application Control IntegrationT1036partialAdaptive Application Control IntegrationT1036.001partialAdaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdvanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001significantAdvanced Anti-Phishing T1566.002significantApp GovernanceT1566significantAdvanced Threat HuntingT1189partialAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1566.002significantDefender for Cloud AppsT1071minimalDefender for Cloud AppsT1189partial
respond · 11 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAdvanced Anti-Phishing T1566.002partialAutomated Investigation and ResponseT1189significantAutomated Investigation and ResponseT1204.001significantAutomated Investigation and ResponseT1204.002significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.001significantAutomated Investigation and ResponseT1566.002significantIncident ResponseT1059minimalIncident ResponseT1566minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1036
Countermeasures · D3FEND
Defensive techniques that counter Bahamut's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.