SideWinder (Windows)

First seen
2012-12-01 00:00:00
Malware type
trojan, spyware
Family
Malware family
Profile updated
2026-07-07 12:57:23

Targeted industries: government-and-public-sector defense-and-aerospace education-and-nonprofits

Targeted regions: country_code:pk country_code:bd country_code:my country_code:sl

Context

SideWinder is a cyber-espionage-focused Advanced Persistent Threat (APT) group known for targeting government and defense sectors in certain South Asian countries. The group employs spear-phishing emails and various malware to conduct surveillance and steal sensitive information. SideWinder has been active since at least 2012.

Related threat objects

Reports & references

  • otx.alienvault.com — 5Fd10760F9Afb730D37C4742 (report)
  • Trend Micro — Sidewinder Leverages South Asian Territorial Issues For Spear Ph (report)
  • s.tencent.com — 659 (report)
  • s.tencent.com — 479 (report)
  • medium.com — Apt Sidewinder Tricks Powershell Anti Forensics And Execution Side Loading 5Bc1A7E7C84C (report)
  • cdn-cybersecurity.att.com — Global Perspective Of The Sidewinder Apt (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sidewinder (report)
  • medium.com — 404 File Still Found D52C3834084C (report)
  • ti.qianxin.com — The Recent Rattlesnake Apt Organized Attacks On Neighboring Countries And Regions (report)
  • embeeresearch.io — Advanced Guide To Infrastructure Analysis Tracking Apt Sidewinder Domains (report)
  • secrss.com — 26507 (report)

External references