Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Sidewinder

Also known as: T-APT-04, Rattlesnake, India, SideWinder, APT-C-17, Razor Tiger, Hardcore Nationalist, T-APT4, Baby Elephant, Leafperforator, BabyElephant, APT Q4, APT Q39, HN2, GroupA21, tracked as, military, businesses throughout Asia, particularly Pakistan

Description

Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.(Citation: ATT Sidewinder January 2021)(Citation: Securelist APT Trends April 2018)(Citation: Cyble Sidewinder September 2020)

Goals & Targeting

Targeted Sectors

Defense
Government
Maritime
Nuclear
Transportation
Healthcare
Critical infrastructure
Hospitality
Financial services
Manufacturing
Education

Targeted Countries / Regions

PK
IN
CN
US
TR
SY

AI Analysis

Grounded in web research
· analyzed in 11 chunks · 1 week ago

Executive Summary

Sidewinder is an Indian‑based threat actor active since at least 2012, primarily conducting espionage against maritime, port, nuclear and high‑profile government entities in South Asia, the Middle East and Africa. The group relies on sophisticated spear‑phishing with malicious LNK attachments, macro‑enabled Office files and fileless delivery chains to deploy its custom WarHawk backdoor and Cobalt Strike implants over HTTP(S). Recent campaigns feature anti‑sandbox checks tied to Pakistani time zones and server‑side polymorphism that allow the actor to maintain long‐term access while evading detection.

Goals & Targeting

Sidewinder seeks to acquire politically relevant intelligence through persistent surveillance of government, military, naval and nuclear assets in South Asia and the broader Near East. By exploiting regional political tensions as lure themes and targeting ports that serve dual civilian/military purposes, the group collects command‑and‑control credentials, device fingerprints and network topology for future exploitation or exfiltration. The focus on maritime trade corridors further suggests strategic motives linked to national defense capabilities and economic espionage. The actor’s targeting profile skews toward high‑profile institutions—government ministries, port authorities, naval shipyards, and nuclear facilities—and extends to healthcare, research and diplomatic organizations when they present opportunities for sensitive data harvest. Recent expansions into the Middle East and Africa indicate an opportunistic scaling strategy aimed at gathering a wide range of geopolitical intelligence. Sidewinder’s operations are executed with long‑term persistence mechanisms, frequent updates to its custom backdoor (WarHawk) and consistent use of commercial code frameworks, enabling them to remain covert while harvesting operational data over months or years.

Enhanced Description

Sidewinder is a clandestine adversary believed to be operating from India, with an operational history that stretches back to 2012. Its core mission is state‑level espionage against a diverse array of targets—military, naval, port and logistic assets as well as nuclear and other strategic infrastructure—in South Asia and beyond. The group has demonstrated a strong preference for maritime ports on the Indian Ocean and the Mediterranean, leveraging political events in its social engineering payloads to lure victims. Tactics center on spear‑phishing that harnesses malicious LNK files, Office documents with embedded macros, JavaScript and VBScript loaders, with delivery frequently masquerading as legitimate services such as Netlify or Outlook. Attackers often embed a small bootstrapper that downloads a WarHawk backdoor or Cobalt Strike beacon from an attacker controlled HTTPS endpoint (e.g., 146.190.235.137). The malware performs anti‑sandbox checks—processor count, RAM, disk size and an explicit Pakistan Standard Time zone check—before proceeding. Post‑infection, Sidewinder’s implants perform extensive automated discovery: registry queries for security software, file & directory enumeration, process discovery, system configuration gathering (network adapters, IP addresses) and acquisition of hardware GUIDs via GetCurrentHWProfileA. The group obfuscates payloads using Base64 or ECDH‑P256 encryption, executes them from memory in a single step (DLL side‑loading and LoadLibrary injection into notepad.exe via the kernel callback table), then exfiltrates data over the same HTTPS channel as benign traffic using JSON payloads that include device identifiers. Persistence is established through registry run keys, startup folder entries and occasionally scheduled tasks. The actor’s toolset further includes StealerBot (for credential theft, keylogging and screen capture), Capriccio, GoSerpent and Mirage Kitten—all of which enable long‑term access in high‑value targets across government, healthcare and diplomatic sectors. Sidewinder has also employed public vulnerability exploits such as CVE‑2017‑11882 to bypass macro policies. Overall, Sidewinder’s campaigns are characterized by sustained, high‑volume operations that blend phishing, web‑based command and control, fileless execution, anti‑sandbox persistence and a heavy focus on strategic maritime infrastructure.

Key Capabilities

  • Spear‑phishing via malicious LNK attachments and macro‑enabled Office documents
  • Targeting maritime, port, logistics, nuclear, government, healthcare and diplomatic sectors in South Asia, the Middle East and Africa
  • Tracking domain and infrastructure using regex patterns, exploiting legitimate services such as Netlify or Outlook
  • Deploying web‑based C2 over HTTP(S) with JSON payloads and GUID‑based beaconing
  • Utilizing automated system, network discovery and collection, including registry run key persistence
  • Delivering custom backdoors like WarHawk that perform DLL side‑loading (rekeywiz.exe) and kernel callback table injection
  • Employing Base64-encoded or ECDH-P256 encrypted scripts for obfuscation
  • Performing anti‑sandbox checks on processor count, memory size, disk capacity and Pakistan Standard Time zone validation
  • Downloading additional staged payloads via ISO files, LNK shortcuts or embedded ClickOnce installers
  • Exfiltrating data over the same HTTPS channel using file‑less techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Discovery
Collection
Exfiltration
Persistence
Defense Evasion
Privilege Escalation
Credential Access

ATT&CK Techniques

T1566.001
T1566.002
T1598.002
T1598.003
T1204.001
T1204.002
T1071.001
T1105
T1119
T1082
T1016
T1033
T1124
T1027
T1027.010
T1027.013
T1059.001
T1059.005
T1059.007
T1547.001
T1559.002
T1518.001
T1574.001
T1083
T1055.001
T1057
T1115

Software / Tooling

WarHawk backdoor
Sidewinder custom tool / SideWinder toolkit
Cobalt Strike
StealerBot
Capriccio RAT
GoSerpent
Mirage Kitten
Koadic
Snitch.exe
OneDrive.exe
DDRA.exe
RtlAudioDriver.exe
MsBuild.exe
mshta

Campaigns & Victims

Sidewinder’s campaign history shows a persistent, high‑volume attack strategy that began in 2012 and has evolved to target increasingly sophisticated assets. Initial operations focused on South Asian governments; recent years have seen the group expand into maritime ports along the Indian Ocean and Mediterranean, the Middle East, and Africa. The actor maintains rapid execution of new delivery vectors—malicious LNK files, macro‑enabled Office documents, ISO files from official sites—and uses server‑side polymorphism to evade detection. Victim types vary from strategic military installations and port authorities to healthcare organizations and research institutions, reflecting a broad intelligence‑gathering mandate. Each campaign typically lasts several weeks, with the attackers layering persistence mechanisms (registry keys, startup folder, scheduled tasks) and leveraging compromised corporate networks for lateral movement. Notable past operations include an early 2018 supply‐chain compromise via a CVE in Microsoft Office, a 2022 campaign that delivered WarHawk through an ISO file hosted on the Nepalese NEPRA site, and a 2023 assault on Turkish maritime ports employing LNK-based loaders to install Cobalt Strike. The group’s modular toolset—combining WarHawk backdoor, StealerBot and other RATs—enables them to maintain long‑term access while scaling operations across multiple regions. Operational tempo remains brisk: the actor often launches new spear‑phishing waves within weeks of each other, updates threat material with current geopolitical events, and re‑initializes compromised infrastructure on a regular basis. Their campaigns rely heavily on low‑cost social‑engineering and publicly available services for delivery, allowing quick adaptation to changing target environments. IOC patterns

IOC Patterns

  • Malicious domain names following regex patterns
  • Malicious LNK files used for download or execution
  • Office documents with embedded macros (Word/Excel)
  • Phishing URLs hosted on legitimate services such as Netlify or Outlook
  • Open directory listings exploited as attack vectors
  • Malicious PDFs and ClickOnce installers
  • HTTP-based C2 communications over HTTPS (JSON payloads)
  • Registry Run Key persistence entries
  • Base64‑encoded PowerShell/VBScript/JavaScript scripts
  • ECDH-P256 encrypted obfuscated payloads
  • DLL side‑loading using legitimate executables such as rekeywiz.exe
  • ActiveXObject OLE creation in Internet Explorer
  • ISO files hosted on nepra.org.pk (32-Advisory–No-32.iso)
  • Malicious URLs mimicking government institutions (e.g., Central Bank of Myanmar)
  • C2 IP 146.190.235.137 and endpoints /wh/, /Snitch.exe, /OneDrive.exe, /DDRA.exe
  • Anti‑sandbox checks: processor count, memory size, disk capacity, time zone verification
  • KernelCallbackTable injection into notepad.exe
  • Memory‑only module loading without disk artifacts
  • GUID-based beaconing using GetCurrentHWProfileA

Recommended Actions

  • Enable granular email filtering to block spear-phishing attachments and LNK file downloads Enforce application whitelisting for PowerShell, VBScript, JavaScript, mshta.exe and other script interpreters Block known malicious domains (regex patterns) and IP addresses such as 146.190.235.137 Deploy endpoint protection with macro-scan rules and detection of DLL side-loading (rekeywiz, etc.) Install EDR solutions that flag fileless execution, in-memory DLL injection, LoadLibrary calls and kernel callback table manipulation Monitor outbound HTTPS traffic for JSON beaconing patterns to known C2 hosts Implement time-zone validation controls to detect region-locked payloads Enforce multi‑factor authentication on privileged accounts Patch public-facing applications promptly, especially WebDAV/CVE vulnerabilities Conduct regular phishing awareness training focusing on LNK attachments, Office macros and cryptocurrency-themed emails Log and analyze system time, processor count and memory attributes for anti-sandbox anomalies Deploy YARA rules specific to Sidewinder payload signatures
  • suggested_tags':['Sidewinder','T-APT-04','Rattlesnake','APT-C-17','India-based','state-sponsored','espionage','maritime sector','nuclear sector','backdoor malware','high-level government institutions','phishing attacks','custom malicious tool','Cobalt Strike','Kernel callback injection','LNK file exploitation','WarHawk','C2 over HTTPS','Beaconing with GUID','Download & execute','Dynamic API resolution','Obfuscated strings','fileless malware','spear-phishing','cryptocurrency-themed emails','credential harvesting','keylogging','screen capture','RAT','MiddleEast expansion','Africa expansion','Asia-Pacific targeting','high-profile infrastructure','government sector','healthcare sector','diplomatic entities','Mirage Kitten','GoSerpent','SideWinder Antibot']
  • confidence_assessment':'The intelligence indicates a moderately high confidence in Sidewinder’s existence, capabilities and target profile based on multiple independent reports spanning several years. Strength lies in corroborated artifacts such as the WarHawk backdoor, documented spear‑phishing campaigns, and observable C2 infrastructure. However, gaps remain regarding precise attribution to a state actor, full geographic coverage of operations, definitive motive beyond espionage, and current activity post‑2019 due to limited recent reports. Continuous monitoring and integration of new threat data are required to update the profile.',

Sources

ATT&CK Techniques

Discovery
8 techniques
Execution
10 techniques
Stealth
12 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 2 Domain 9 IPv4 Address 1 Filename 8

References

  1. Cyble Sidewinder September 2020 — Cyble. (2020, September 26). SideWinder APT Targets with futuristic Tactics and Techniques. Retrieved January 29, 2021.
  2. Securelist APT Trends April 2018 — Global Research and Analysis Team . (2018, April 12). APT Trends report Q1 2018. Retrieved January 27, 2021.
  3. ATT Sidewinder January 2021 — Hegel, T. (2021, January 13). A Global Perspective of the SideWinder APT. Retrieved January 27, 2021.
  4. www.zscaler.com — Cited by web research for: T-APT4
  5. attack.mitre.org — Cited by web research for: T1059
  6. www.huntress.com — Cited by web research for: Unknown
  7. www.kaspersky.com — Cited by web research for: Mirage
  8. apt.etda.or.th — Cited by web research for: Leverage
  9. www.trellix.com — Cited by web research for: curl
  10. www.group-ib.com — Cited by web research for: Financial Services

Intel Summary

47

Techniques

53

Tools

0

Campaigns

132

IOCs

0

Observed Data

9

Tactics

Tags

APT
Government Targeting
espionage
government
defense

Details

MITRE ID
G0121
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
90%
Added
Jul 13, 2026
STIX ID
intrusion-set--3fc023b2-c5cc-481d-9c3e-70141ae1a87e
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.