Beyond the Surface: the evolution and expansion of the SideWinder APT group
What it means
MISP EudorIA ha pubblicato l'advisory "Beyond the Surface: the evolution and expansion of the SideWinder APT group". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: Beyond the Surface: the evolution and expansion of the SideWinder APT group. Report from - [URL rimossa] (1729443624) SideWinder, aka T-APT-04 or RattleSnake, is one of the most prolific APT groups that began its activities in 2012 and was first publicly mentioned by us in 2018. Over the years, the group has launched attacks against high-profile entities in South and Southeast Asia. Its primary targets have been military and government entities in Pakistan, Sri Lanka, China and Nepal. Over the years, SideWinder has carried out an impressive number of attacks and its activities have been extensively described in various analyses and reports published by different researchers and vendors (for example, here, here and here), one of the latest of which was released at the end of July 2024. The group may be perceived as a low-skilled actor due to the use of public exploits, malicious LNK files and scripts as infection vectors, and the use of public RATs, but their true capabilities only become apparent when you carefully examine the details of their operations. Despite years of observation and study, knowledge of their post-compromise activities remains limited. During our investigation, we observed new waves of attacks that showed a significant expansion of the group’s activities. The attacks began to impact high-profile entities and strategic infrastructures in the Middle East and Africa, and we also discovered a previously unknown post-exploitation toolkit
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it · translation not needed
- Publication
- 30/07/2026 02:52
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 145
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 145Last sharing verification: 2026-09-26T04:30:42.721661+00:00
- MISP event
- 273d8b6d-8d50-4bf2-b36d-1f306aabc438
- Classification
- Medium
- Group attributed by the source
- Sidewinder - G0121