Windshift
MITRE ATT&CK: G0112 View on attack.mitre.org
Aliases: Bahamut, Windy Phoenix, Windshift
- First seen
- 2017-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 8 (8 malicious)
- Last IoC activity
- 2026-09-01 20:38:19
- Profile updated
- 2026-07-07 11:57:39
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:ae country_code:sa country_code:qa
Context
Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.
Recent IoC activity
8 malicious indicators in Maltiverse are attributed to Windshift (G0112). The 8 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | www.dservices.space | 2026-09-03 | 1 |
| hostname | 96r1yh643o.de | 2026-09-02 | 1 |
| hostname | r4dc3btbyzip0edkbykb1qteulwb.de | 2026-08-16 | 1 |
| hostname | 32e6dwbbpg.de | 2026-05-05 | 1 |
| hostname | www.kmickejbb9.de | 2026-04-16 | 1 |
| hostname | kmickejbb9.de | 2026-04-08 | 1 |
| hostname | www.r4dc3btbyzip0edkbykb1qteulwb.de | 2026-01-18 | 1 |
| hostname | hbx5adg6vk.de | 2025-09-23 | 2 |
Detection coverage
- 460 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Visual Basic (attack-pattern)
- Security Software Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Malicious Link (attack-pattern)
- Spearphishing via Service (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Software Discovery (attack-pattern)
- Spearphishing Link (attack-pattern)
- Invalid Code Signature (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Web Protocols (attack-pattern)
- Masquerading (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Malicious File (attack-pattern)
- Contact List (attack-pattern)
- System Checks (attack-pattern)
- Conceal Multimedia Files (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Audio Capture (attack-pattern)
- Data from Local System (attack-pattern)
Reports & references
- Palo Alto Unit 42 — Shifting In The Wind Windshift Attacks Target Middle Eastern Governments (report)
- gsec.hitb.org — D1%20Commsec%20 %20In%20The%20Trails%20Of%20Windshift%20Apt%20 %20Taha%20Karim (report)
- Palo Alto Unit 42 — Windyphoenix (report)
- MITRE ATT&CK — G0112 (report)
- objective-see.com — Blog 0X3B (report)
- objective-see.com — Blog 0X3D (report)
- scribd.com — Windshift Summit Archive 1554718868 (report)