◇ SIGN IN
← all actors
apt

SideWinder

activemedium confidence
APT / State-sponsored
RattlesnakeT-APT-04APT-C-17RAZOR TIGERHardcore Nationalist
Attribution
Suspected Indian-nexus espionage group
Origin
India (suspected)
First seen
2018
Last active
2025
Motivation
Espionage
Confidence
medium
MENA targeting
Egypt (primary MENA focus, H2 2024), Djibouti, UAE
Sectors
Maritime/port authorities, nuclear/energy agencies, government, military, diplomatic, logistics, telecom
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Egypt (primary MENA focus, H2 2024), Djibouti (Maritime/port authorities, nuclear/energy agencies, government sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

SideWinder (MITRE G0121) is a suspected Indian-nexus espionage group historically focused on South Asia that has, in 2024-2025, expanded aggressively into maritime, nuclear, and IT/government targets across the Middle East and Africa.

History

SideWinder has operated since at least 2012 and was catalogued by MITRE as G0121 (aliases Rattlesnake, T-APT-04). It is assessed with medium-to-high confidence to be Indian-nexus, historically prioritizing government, military and diplomatic targets in Pakistan, China, Nepal, Afghanistan and Sri Lanka.

The group's infection chain is well characterized: spear-phishing emails carry DOCX attachments using remote template injection to fetch RTF files that exploit the old Microsoft Equation Editor flaw CVE-2017-11882, executing shellcode that loads a Backdoor Loader and ultimately the modular StealerBot espionage toolkit. SideWinder iterates rapidly on loaders and obfuscation, earning a reputation for agile retooling.

MENA relevance grew sharply in 2024-2025. Kaspersky and others documented campaigns against maritime and logistics companies and critical infrastructure spanning Djibouti, Egypt and the United Arab Emirates (alongside Bangladesh, Cambodia and Vietnam), plus targeting of nuclear power and energy-related organizations. In 2025, activity clustered first in Djibouti, then shifted to Egypt, with continued nuclear-sector interest.

Confidence in the activity is high given consistent Kaspersky/vendor telemetry; the Indian-nexus attribution is a medium-confidence assessment. Its inclusion here reflects the significant Egypt, Djibouti and UAE targeting rather than a Middle Eastern origin.

Notable campaigns

2020-2021
South Asian government targeting
Sustained spear-phishing against government and military entities in Pakistan, Nepal and Afghanistan using Equation Editor exploits.
2024
Maritime and logistics expansion
Kaspersky observed attacks on maritime/logistics firms across Djibouti, Egypt, the UAE and South/Southeast Asia.
2025
Maritime and nuclear sector campaign
Refined spear-phishing delivered Backdoor Loader and StealerBot against nuclear and critical-infrastructure targets, with activity shifting from Djibouti to Egypt.

Observed ATT&CK techniques · 30

TechniqueNameTacticObserved use
T1074.001Data Staged: Local Data StagingcollectionCollected stolen files in a temporary folder in preparation for exfiltration
T1119Automated CollectioncollectionTools to automatically collect system and network configuration information
T1071.001Application Layer Protocol: Web Protocolscommand and controlHTTP in C2 communications
T1105Ingress Tool Transfercommand and controlLNK files to download remote files to victim networks
T1218.005System Binary Proxy Execution: Mshtadefense evasionUsed mshta.exe to execute malicious payloads
T1036.005Masquerading: Match Legitimate Resource Name or Locationdefense evasionNamed malicious files rekeywiz.exe to match legitimate Windows executable
T1027.010Obfuscated Files or Information: Command Obfuscationdefense evasionBase64 encoding for scripts
T1027.013Obfuscated Files or Information: Encrypted/Encoded Filedefense evasionBase64 encoding and ECDH-P256 encryption for payloads
T1057Process DiscoverydiscoveryTools to identify running processes on victim machines
T1518.001Software Discovery: Security Software DiscoverydiscoveryWindows service winmgmts to check installed antivirus products
T1518Software DiscoverydiscoveryTools to enumerate software installed on infected hosts
T1083File and Directory DiscoverydiscoveryMalware to collect information on files and directories
T1033System Owner/User DiscoverydiscoveryTools to identify the user of a compromised host
T1016System Network Configuration DiscoverydiscoveryMalware to collect network interface information including MAC addresses
T1124System Time DiscoverydiscoveryTools to obtain current system time
T1082System Information DiscoverydiscoveryTools to collect computer name, OS version, hotfixes, memory and processor info
T1204.001User Execution: Malicious LinkexecutionLured targets to click malicious links for execution
T1203Exploitation for Client ExecutionexecutionExploited vulnerabilities including CVE-2017-11882 and CVE-2020-0674
T1059.001Command and Scripting Interpreter: PowerShellexecutionPowerShell to drop and execute malware loaders
T1059.005Command and Scripting Interpreter: Visual BasicexecutionVBScript to drop and execute malware loaders
T1059.007Command and Scripting Interpreter: JavaScriptexecutionJavaScript to drop and execute malware loaders
T1204.002User Execution: Malicious FileexecutionLured targets to click malicious files for execution
T1559.002Inter-Process Communication: Dynamic Data ExchangeexecutionActiveXObject utility to create OLE objects for execution through Internet Explorer
T1574.001Hijack Execution Flow: DLLexecution/defense evasionDLL side-loading to drop malicious payloads, hijacking rekeywiz.exe
T1020Automated ExfiltrationexfiltrationConfigured tools to automatically send collected files to attacker controlled servers
T1566.001Phishing: Spearphishing Attachmentinitial accessSent emails with malicious attachments crafted for specific targets
T1566.002Phishing: Spearphishing Linkinitial accessSent emails with malicious links crafted for specific targets
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup FolderpersistenceAdded paths to executables in the Registry to establish persistence
T1598.002Phishing for Information: Spearphishing AttachmentreconnaissanceEmails with malicious attachments leading to credential harvesting sites
T1598.003Phishing for Information: Spearphishing LinkreconnaissanceEmails with malicious links to credential harvesting websites