Windshift

MITRE ATT&CK: G0112 View on attack.mitre.org

Aliases: Bahamut, Windy Phoenix, Windshift

First seen
2017-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
8 (8 malicious)
Last IoC activity
2026-09-01 20:38:19
Profile updated
2026-07-07 11:57:39

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:ae country_code:sa country_code:qa

Context

Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.

Recent IoC activity

8 malicious indicators in Maltiverse are attributed to Windshift (G0112). The 8 most recently updated:

TypeIndicatorUpdatedSources
hostname www.dservices.space 2026-09-03 1
hostname 96r1yh643o.de 2026-09-02 1
hostname r4dc3btbyzip0edkbykb1qteulwb.de 2026-08-16 1
hostname 32e6dwbbpg.de 2026-05-05 1
hostname www.kmickejbb9.de 2026-04-16 1
hostname kmickejbb9.de 2026-04-08 1
hostname www.r4dc3btbyzip0edkbykb1qteulwb.de 2026-01-18 1
hostname hbx5adg6vk.de 2025-09-23 2

Detection coverage

  • 460 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Visual Basic (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Malicious Link (attack-pattern)
  • Spearphishing via Service (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Software Discovery (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Invalid Code Signature (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Web Protocols (attack-pattern)
  • Masquerading (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • Contact List (attack-pattern)
  • System Checks (attack-pattern)
  • Conceal Multimedia Files (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Audio Capture (attack-pattern)
  • Data from Local System (attack-pattern)

Reports & references

  • Palo Alto Unit 42 — Shifting In The Wind Windshift Attacks Target Middle Eastern Governments (report)
  • gsec.hitb.org — D1%20Commsec%20 %20In%20The%20Trails%20Of%20Windshift%20Apt%20 %20Taha%20Karim (report)
  • Palo Alto Unit 42 — Windyphoenix (report)
  • MITRE ATT&CK — G0112 (report)
  • objective-see.com — Blog 0X3B (report)
  • objective-see.com — Blog 0X3D (report)
  • scribd.com — Windshift Summit Archive 1554718868 (report)

External references