Windshift
Aliases: Bahamut
Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.
Open interactive actor investigation
ATT&CK techniques
T1057
Process DiscoveryT1189
Drive-by CompromiseT1059.005
Visual BasicT1518.001
Security Software DiscoveryT1566.001
Spearphishing AttachmentT1204.001
Malicious LinkT1566.003
Spearphishing via ServiceT1547.001
Registry Run Keys / Startup FolderT1518
Software DiscoveryT1566.002
Spearphishing LinkT1036.001
Invalid Code SignatureT1027
Obfuscated Files or InformationT1071.001
Web ProtocolsT1036
MasqueradingT1105
Ingress Tool TransferT1047
Windows Management InstrumentationT1033
System Owner/User DiscoveryT1082
System Information DiscoveryT1204.002
Malicious File
Process DiscoveryT1189
Drive-by CompromiseT1059.005
Visual BasicT1518.001
Security Software DiscoveryT1566.001
Spearphishing AttachmentT1204.001
Malicious LinkT1566.003
Spearphishing via ServiceT1547.001
Registry Run Keys / Startup FolderT1518
Software DiscoveryT1566.002
Spearphishing LinkT1036.001
Invalid Code SignatureT1027
Obfuscated Files or InformationT1071.001
Web ProtocolsT1036
MasqueradingT1105
Ingress Tool TransferT1047
Windows Management InstrumentationT1033
System Owner/User DiscoveryT1082
System Information DiscoveryT1204.002
Malicious File