SideWinder (MITRE G0121) is a suspected Indian-nexus espionage group historically focused on South Asia that has, in 2024-2025, expanded aggressively into maritime, nuclear, and IT/government targets across the Middle East and Africa.
SideWinder has operated since at least 2012 and was catalogued by MITRE as G0121 (aliases Rattlesnake, T-APT-04). It is assessed with medium-to-high confidence to be Indian-nexus, historically prioritizing government, military and diplomatic targets in Pakistan, China, Nepal, Afghanistan and Sri Lanka.
The group's infection chain is well characterized: spear-phishing emails carry DOCX attachments using remote template injection to fetch RTF files that exploit the old Microsoft Equation Editor flaw CVE-2017-11882, executing shellcode that loads a Backdoor Loader and ultimately the modular StealerBot espionage toolkit. SideWinder iterates rapidly on loaders and obfuscation, earning a reputation for agile retooling.
MENA relevance grew sharply in 2024-2025. Kaspersky and others documented campaigns against maritime and logistics companies and critical infrastructure spanning Djibouti, Egypt and the United Arab Emirates (alongside Bangladesh, Cambodia and Vietnam), plus targeting of nuclear power and energy-related organizations. In 2025, activity clustered first in Djibouti, then shifted to Egypt, with continued nuclear-sector interest.
Confidence in the activity is high given consistent Kaspersky/vendor telemetry; the Indian-nexus attribution is a medium-confidence assessment. Its inclusion here reflects the significant Egypt, Djibouti and UAE targeting rather than a Middle Eastern origin.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1074.001 ↗ | Data Staged: Local Data Staging | collection | Collected stolen files in a temporary folder in preparation for exfiltration |
| T1119 ↗ | Automated Collection | collection | Tools to automatically collect system and network configuration information |
| T1071.001 ↗ | Application Layer Protocol: Web Protocols | command and control | HTTP in C2 communications |
| T1105 ↗ | Ingress Tool Transfer | command and control | LNK files to download remote files to victim networks |
| T1218.005 ↗ | System Binary Proxy Execution: Mshta | defense evasion | Used mshta.exe to execute malicious payloads |
| T1036.005 ↗ | Masquerading: Match Legitimate Resource Name or Location | defense evasion | Named malicious files rekeywiz.exe to match legitimate Windows executable |
| T1027.010 ↗ | Obfuscated Files or Information: Command Obfuscation | defense evasion | Base64 encoding for scripts |
| T1027.013 ↗ | Obfuscated Files or Information: Encrypted/Encoded File | defense evasion | Base64 encoding and ECDH-P256 encryption for payloads |
| T1057 ↗ | Process Discovery | discovery | Tools to identify running processes on victim machines |
| T1518.001 ↗ | Software Discovery: Security Software Discovery | discovery | Windows service winmgmts to check installed antivirus products |
| T1518 ↗ | Software Discovery | discovery | Tools to enumerate software installed on infected hosts |
| T1083 ↗ | File and Directory Discovery | discovery | Malware to collect information on files and directories |
| T1033 ↗ | System Owner/User Discovery | discovery | Tools to identify the user of a compromised host |
| T1016 ↗ | System Network Configuration Discovery | discovery | Malware to collect network interface information including MAC addresses |
| T1124 ↗ | System Time Discovery | discovery | Tools to obtain current system time |
| T1082 ↗ | System Information Discovery | discovery | Tools to collect computer name, OS version, hotfixes, memory and processor info |
| T1204.001 ↗ | User Execution: Malicious Link | execution | Lured targets to click malicious links for execution |
| T1203 ↗ | Exploitation for Client Execution | execution | Exploited vulnerabilities including CVE-2017-11882 and CVE-2020-0674 |
| T1059.001 ↗ | Command and Scripting Interpreter: PowerShell | execution | PowerShell to drop and execute malware loaders |
| T1059.005 ↗ | Command and Scripting Interpreter: Visual Basic | execution | VBScript to drop and execute malware loaders |
| T1059.007 ↗ | Command and Scripting Interpreter: JavaScript | execution | JavaScript to drop and execute malware loaders |
| T1204.002 ↗ | User Execution: Malicious File | execution | Lured targets to click malicious files for execution |
| T1559.002 ↗ | Inter-Process Communication: Dynamic Data Exchange | execution | ActiveXObject utility to create OLE objects for execution through Internet Explorer |
| T1574.001 ↗ | Hijack Execution Flow: DLL | execution/defense evasion | DLL side-loading to drop malicious payloads, hijacking rekeywiz.exe |
| T1020 ↗ | Automated Exfiltration | exfiltration | Configured tools to automatically send collected files to attacker controlled servers |
| T1566.001 ↗ | Phishing: Spearphishing Attachment | initial access | Sent emails with malicious attachments crafted for specific targets |
| T1566.002 ↗ | Phishing: Spearphishing Link | initial access | Sent emails with malicious links crafted for specific targets |
| T1547.001 ↗ | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | persistence | Added paths to executables in the Registry to establish persistence |
| T1598.002 ↗ | Phishing for Information: Spearphishing Attachment | reconnaissance | Emails with malicious attachments leading to credential harvesting sites |
| T1598.003 ↗ | Phishing for Information: Spearphishing Link | reconnaissance | Emails with malicious links to credential harvesting websites |