Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Windshift

Also known as: Bahamut, Offshore APT organization from South Asia, Windy Phoenix, tracked as, forecasts, a solitary arcus, KitM OSX, Tech Sectors, Agrius

Description

Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.(Citation: SANS Windshift August 2018)(Citation: objective-see windtail1 dec 2018)(Citation: objective-see windtail2 jan 2019)

Goals & Targeting

Targeted Sectors

Government
Critical infrastructure
Energy
Nuclear
Transportation
Media
Financial services
Maritime
Education
Mining
Non profit

Targeted Countries / Regions

middle_east
UA
AE
KP
PK
IN
VN
EG
MX
RU

AI Analysis

· 1 week ago

Executive Summary

Windshift, also known as Bahamut or Offshore APT, is an advanced persistent threat (APT) group primarily involved in espionage activities targeting Middle Eastern governments and critical infrastructure since at least 2017. The group employs sophisticated tactics including spear-phishing campaigns and malware deployment to achieve its objectives.

Goals & Targeting

Windshift's primary motivation is espionage, targeting Middle Eastern countries for strategic intelligence. The group specifically focuses on government departments and critical infrastructure sectors due to their high-value assets and the potential impact of compromising such entities.

Enhanced Description

Windshift has been actively conducting surveillance operations in the Middle East, focusing on government departments and critical infrastructure sectors. Known for their use of custom tools like WindTail, the group leverages a variety of techniques including system discovery, file obfuscation, and malicious document dissemination to compromise targets. Their operations often involve long-term campaigns aimed at gathering sensitive information, demonstrating a high level of operational persistence.

Key Capabilities

  • Spear-phishing with attachments
  • Malicious file distribution
  • Custom malware (WindTail)
  • Obfuscation techniques
  • Registry modifications for persistence

MITRE ATT&CK Tactics

Discovery
Defense Evasion
Credential Access
Collection
Exfiltration
Execution

ATT&CK Techniques

T1047
T1033
T1204.002
T1566.002
T1566.001
T1082
T1036
T1057
T1547.001
T1027
T1036.001
T1518.001
T1189
T1071.001
T1059.005
T1518
T1105
T1204.001
T1566.003

Software / Tooling

WindTail

Campaigns & Victims

Windshift is known for long-term campaigns targeting specific individuals in government and critical infrastructure sectors. Their operations include the use of spear-phishing emails with malicious attachments or links, aiming to maintain persistence on compromised systems.

IOC Patterns

  • Spear-phishing emails with maliciousattachments
  • Malicious files dropped during infections
  • Registry changes for persistence

Recommended Actions

  • Implement email filtering to detect spear-phishing attempts
  • Monitor for suspicious file hashes related to WindTail malware
  • Harden system configurations to prevent arbitrary execution of scripts.
  • Employ endpoint detection and response (EDR) solutions to monitor for T1047 behavior.
  • Conduct regular user training on recognizing phishing tactics.

Suggested Tags

APT
espionage
Middle East

Confidence Assessment

Moderate confidence level. While the group's TTPs and targets are well-documented, there is limited visibility into their precise campaign timelines and exact objectives beyond espionage. Additional information on their infrastructure and specific campaigns could enhance understanding.

ATT&CK Techniques

Credential Access
1 technique
Stealth
14 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 9 Domain 7 SHA-256 Hash 3 IPv4 Address 1

References

  1. SANS Windshift August 2018 — Karim, T. (2018, August). TRAILS OF WINDSHIFT. Retrieved November 17, 2024.
  2. objective-see windtail1 dec 2018 — Wardle, Patrick. (2018, December 20). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 1). Retrieved October 3, 2019.
  3. objective-see windtail2 jan 2019 — Wardle, Patrick. (2019, January 15). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 2). Retrieved October 3, 2019.
  4. attack.mitre.org — Cited by web research for: Tech Sectors
  5. docs.rapid7.com — Cited by web research for: T1583
  6. attack.mitre.org — Cited by web research for: T1071
  7. unit42.paloaltonetworks.com — Cited by web research for: 109.235.51.110

Intel Summary

48

Techniques

42

Tools

0

Campaigns

41

IOCs

0

Observed Data

9

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
espionage
Middle East

Details

MITRE ID
G0112
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
Canada (CA)
Confidence
90%
Added
Jul 13, 2026
STIX ID
intrusion-set--afec6dc3-a18e-4b62-b1a4-5510e1a498d1
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.