Also known as: Bahamut, Offshore APT organization from South Asia, Windy Phoenix, tracked as, forecasts, a solitary arcus, KitM OSX, Tech Sectors, Agrius
Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.(Citation: SANS Windshift August 2018)(Citation: objective-see windtail1 dec 2018)(Citation: objective-see windtail2 jan 2019)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Windshift, also known as Bahamut or Offshore APT, is an advanced persistent threat (APT) group primarily involved in espionage activities targeting Middle Eastern governments and critical infrastructure since at least 2017. The group employs sophisticated tactics including spear-phishing campaigns and malware deployment to achieve its objectives.
Goals & Targeting
Windshift's primary motivation is espionage, targeting Middle Eastern countries for strategic intelligence. The group specifically focuses on government departments and critical infrastructure sectors due to their high-value assets and the potential impact of compromising such entities.
Enhanced Description
Windshift has been actively conducting surveillance operations in the Middle East, focusing on government departments and critical infrastructure sectors. Known for their use of custom tools like WindTail, the group leverages a variety of techniques including system discovery, file obfuscation, and malicious document dissemination to compromise targets. Their operations often involve long-term campaigns aimed at gathering sensitive information, demonstrating a high level of operational persistence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Windshift is known for long-term campaigns targeting specific individuals in government and critical infrastructure sectors. Their operations include the use of spear-phishing emails with malicious attachments or links, aiming to maintain persistence on compromised systems.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence level. While the group's TTPs and targets are well-documented, there is limited visibility into their precise campaign timelines and exact objectives beyond espionage. Additional information on their infrastructure and specific campaigns could enhance understanding.
No campaigns linked yet.
No observed data linked yet.
48
Techniques
42
Tools
0
Campaigns
41
IOCs
0
Observed Data
9
Tactics