Sidewinder
Aliases: T-APT-04, Rattlesnake
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.
Open interactive actor investigation
ATT&CK techniques
T1203
Exploitation for Client ExecutionT1518.001
Security Software DiscoveryT1218.005
MshtaT1598.003
Spearphishing LinkT1124
System Time DiscoveryT1566.002
Spearphishing LinkT1074.001
Local Data StagingT1057
Process DiscoveryT1059.007
JavaScriptT1027.013
Encrypted/Encoded FileT1020
Automated ExfiltrationT1105
Ingress Tool TransferT1547.001
Registry Run Keys / Startup FolderT1071.001
Web ProtocolsT1559.002
Dynamic Data ExchangeT1083
File and Directory DiscoveryT1016
System Network Configuration DiscoveryT1598.002
Spearphishing AttachmentT1027.010
Command ObfuscationT1059.001
PowerShellT1518
Software DiscoveryT1059.005
Visual BasicT1082
System Information DiscoveryT1119
Automated CollectionT1566.001
Spearphishing AttachmentT1036.005
Match Legitimate Name or LocationT1204.001
Malicious LinkT1204.002
Malicious FileT1033
System Owner/User DiscoveryT1574.002
DLL Side-Loading
Exploitation for Client ExecutionT1518.001
Security Software DiscoveryT1218.005
MshtaT1598.003
Spearphishing LinkT1124
System Time DiscoveryT1566.002
Spearphishing LinkT1074.001
Local Data StagingT1057
Process DiscoveryT1059.007
JavaScriptT1027.013
Encrypted/Encoded FileT1020
Automated ExfiltrationT1105
Ingress Tool TransferT1547.001
Registry Run Keys / Startup FolderT1071.001
Web ProtocolsT1559.002
Dynamic Data ExchangeT1083
File and Directory DiscoveryT1016
System Network Configuration DiscoveryT1598.002
Spearphishing AttachmentT1027.010
Command ObfuscationT1059.001
PowerShellT1518
Software DiscoveryT1059.005
Visual BasicT1082
System Information DiscoveryT1119
Automated CollectionT1566.001
Spearphishing AttachmentT1036.005
Match Legitimate Name or LocationT1204.001
Malicious LinkT1204.002
Malicious FileT1033
System Owner/User DiscoveryT1574.002
DLL Side-Loading