Also known as: T-APT-04, Rattlesnake, India, SideWinder, APT-C-17, Razor Tiger, Hardcore Nationalist, T-APT4, Baby Elephant, Leafperforator, BabyElephant, APT Q4, APT Q39, HN2, GroupA21, tracked as, military, businesses throughout Asia, particularly Pakistan
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.(Citation: ATT Sidewinder January 2021)(Citation: Securelist APT Trends April 2018)(Citation: Cyble Sidewinder September 2020)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Sidewinder is an Indian‑based threat actor active since at least 2012, primarily conducting espionage against maritime, port, nuclear and high‑profile government entities in South Asia, the Middle East and Africa. The group relies on sophisticated spear‑phishing with malicious LNK attachments, macro‑enabled Office files and fileless delivery chains to deploy its custom WarHawk backdoor and Cobalt Strike implants over HTTP(S). Recent campaigns feature anti‑sandbox checks tied to Pakistani time zones and server‑side polymorphism that allow the actor to maintain long‐term access while evading detection.
Goals & Targeting
Sidewinder seeks to acquire politically relevant intelligence through persistent surveillance of government, military, naval and nuclear assets in South Asia and the broader Near East. By exploiting regional political tensions as lure themes and targeting ports that serve dual civilian/military purposes, the group collects command‑and‑control credentials, device fingerprints and network topology for future exploitation or exfiltration. The focus on maritime trade corridors further suggests strategic motives linked to national defense capabilities and economic espionage. The actor’s targeting profile skews toward high‑profile institutions—government ministries, port authorities, naval shipyards, and nuclear facilities—and extends to healthcare, research and diplomatic organizations when they present opportunities for sensitive data harvest. Recent expansions into the Middle East and Africa indicate an opportunistic scaling strategy aimed at gathering a wide range of geopolitical intelligence. Sidewinder’s operations are executed with long‑term persistence mechanisms, frequent updates to its custom backdoor (WarHawk) and consistent use of commercial code frameworks, enabling them to remain covert while harvesting operational data over months or years.
Enhanced Description
Sidewinder is a clandestine adversary believed to be operating from India, with an operational history that stretches back to 2012. Its core mission is state‑level espionage against a diverse array of targets—military, naval, port and logistic assets as well as nuclear and other strategic infrastructure—in South Asia and beyond. The group has demonstrated a strong preference for maritime ports on the Indian Ocean and the Mediterranean, leveraging political events in its social engineering payloads to lure victims. Tactics center on spear‑phishing that harnesses malicious LNK files, Office documents with embedded macros, JavaScript and VBScript loaders, with delivery frequently masquerading as legitimate services such as Netlify or Outlook. Attackers often embed a small bootstrapper that downloads a WarHawk backdoor or Cobalt Strike beacon from an attacker controlled HTTPS endpoint (e.g., 146.190.235.137). The malware performs anti‑sandbox checks—processor count, RAM, disk size and an explicit Pakistan Standard Time zone check—before proceeding. Post‑infection, Sidewinder’s implants perform extensive automated discovery: registry queries for security software, file & directory enumeration, process discovery, system configuration gathering (network adapters, IP addresses) and acquisition of hardware GUIDs via GetCurrentHWProfileA. The group obfuscates payloads using Base64 or ECDH‑P256 encryption, executes them from memory in a single step (DLL side‑loading and LoadLibrary injection into notepad.exe via the kernel callback table), then exfiltrates data over the same HTTPS channel as benign traffic using JSON payloads that include device identifiers. Persistence is established through registry run keys, startup folder entries and occasionally scheduled tasks. The actor’s toolset further includes StealerBot (for credential theft, keylogging and screen capture), Capriccio, GoSerpent and Mirage Kitten—all of which enable long‑term access in high‑value targets across government, healthcare and diplomatic sectors. Sidewinder has also employed public vulnerability exploits such as CVE‑2017‑11882 to bypass macro policies. Overall, Sidewinder’s campaigns are characterized by sustained, high‑volume operations that blend phishing, web‑based command and control, fileless execution, anti‑sandbox persistence and a heavy focus on strategic maritime infrastructure.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Sidewinder’s campaign history shows a persistent, high‑volume attack strategy that began in 2012 and has evolved to target increasingly sophisticated assets. Initial operations focused on South Asian governments; recent years have seen the group expand into maritime ports along the Indian Ocean and Mediterranean, the Middle East, and Africa. The actor maintains rapid execution of new delivery vectors—malicious LNK files, macro‑enabled Office documents, ISO files from official sites—and uses server‑side polymorphism to evade detection. Victim types vary from strategic military installations and port authorities to healthcare organizations and research institutions, reflecting a broad intelligence‑gathering mandate. Each campaign typically lasts several weeks, with the attackers layering persistence mechanisms (registry keys, startup folder, scheduled tasks) and leveraging compromised corporate networks for lateral movement. Notable past operations include an early 2018 supply‐chain compromise via a CVE in Microsoft Office, a 2022 campaign that delivered WarHawk through an ISO file hosted on the Nepalese NEPRA site, and a 2023 assault on Turkish maritime ports employing LNK-based loaders to install Cobalt Strike. The group’s modular toolset—combining WarHawk backdoor, StealerBot and other RATs—enables them to maintain long‑term access while scaling operations across multiple regions. Operational tempo remains brisk: the actor often launches new spear‑phishing waves within weeks of each other, updates threat material with current geopolitical events, and re‑initializes compromised infrastructure on a regular basis. Their campaigns rely heavily on low‑cost social‑engineering and publicly available services for delivery, allowing quick adaptation to changing target environments. IOC patterns
IOC Patterns
Recommended Actions
Sources
No campaigns linked yet.
No observed data linked yet.
47
Techniques
53
Tools
0
Campaigns
132
IOCs
0
Observed Data
9
Tactics