SideWinder (MITRE G0121) is a suspected Indian-nexus espionage group historically focused on South Asia that has, in 2024-2025, expanded aggressively into maritime, nuclear, and IT/government targets across the Middle East and Africa.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
SideWinder has operated since at least 2012 and was catalogued by MITRE as G0121 (aliases Rattlesnake, T-APT-04). It is assessed with medium-to-high confidence to be Indian-nexus, historically prioritizing government, military and diplomatic targets in Pakistan, China, Nepal, Afghanistan and Sri Lanka.
The group's infection chain is well characterized: spear-phishing emails carry DOCX attachments using remote template injection to fetch RTF files that exploit the old Microsoft Equation Editor flaw CVE-2017-11882, executing shellcode that loads a Backdoor Loader and ultimately the modular StealerBot espionage toolkit. SideWinder iterates rapidly on loaders and obfuscation, earning a reputation for agile retooling.
MENA relevance grew sharply in 2024-2025. Kaspersky and others documented campaigns against maritime and logistics companies and critical infrastructure spanning Djibouti, Egypt and the United Arab Emirates (alongside Bangladesh, Cambodia and Vietnam), plus targeting of nuclear power and energy-related organizations. In 2025, activity clustered first in Djibouti, then shifted to Egypt, with continued nuclear-sector interest.
Confidence in the activity is high given consistent Kaspersky/vendor telemetry; the Indian-nexus attribution is a medium-confidence assessment. Its inclusion here reflects the significant Egypt, Djibouti and UAE targeting rather than a Middle Eastern origin.
+24 more relationships — see the relationships browser.