news.mlab.sh
Threat intelligence
Threat actor

SideWinder

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
India
First seen
2012-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Defense, Government, Maritime and Shipbuilding
TLP
WHITE

(Kaspersky) An actor mainly targeting Pakistan military targets, active since at least 2012. We have low confidence that this malware might be authored by an Indian company. To spread the malware, they use unique implementations to leverage the exploits of known vulnerabilities (such as CVE-2017-11882) and later deploy a Powershell payload in the final stages.

Also known as

APT-C-17APT-Q-39BabyElephantG0121GroupA21Hardcore NationalistHN2RattlesnakeRazor TigerSideWinderT-APT-04

Vulnerabilities exploited

Tooling and malware

Koadic

MITRE ATT&CK techniques

T1119 Automated CollectionT1105 Ingress Tool TransferT1016 System Network Configuration DiscoveryT1033 System Owner/User DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1124 System Time DiscoveryT1518 Software DiscoveryT1203 Exploitation for Client ExecutionT1020 Automated Exfiltration

Coverage 2