Sidewinder

MITRE ATT&CK: G0121 View on attack.mitre.org

Aliases: T-APT-04, Rattlesnake, SideWinder, APT-C-17, Sidewinder

First seen
2012-01-01 00:00:00
Origin
IN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
390 (225 malicious)
Last IoC activity
2026-09-02 00:38:45
Profile updated
2026-07-07 11:58:49

Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:pk country_code:cn country_code:np country_code:af

Context

Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.

Recent IoC activity

225 malicious indicators in Maltiverse are attributed to Sidewinder (G0121). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname elccorp-net.ntc-telecomcorporation.workers.dev 2026-09-03 1
hostname mail-hit-gov-pk.ntc-telecomcorporation.workers.dev 2026-09-03 1
hostname offer-ptclnetpk.servehttp.com 2026-09-03 1
hostname www.franceconsobanque.fr 2026-09-03 2
hostname news.ntc-telecomcorporation.workers.dev 2026-09-03 1
hostname president-gov-lk.donwloaded.net 2026-09-03 1
hostname mofa-gov-pk.dowmload.co 2026-09-03 1
hostname support-ntc.servehttp.com 2026-09-02 1
hostname president-gov-ik.donwloaded.net 2026-09-02 1
hostname mail-modp-gov-pk.pak-gov-pk.workers.dev 2026-09-02 1
hostname mail-modp-gov-pk.ntc-telecomcorporation.workers.dev 2026-09-02 1
hostname hrmis-financegovpk.serveftp.com 2026-09-02 1
hostname cloud-ptclnetpk.servehttp.com 2026-09-02 1
hostname mail-paf-gov-pk.ntc-telecomcorporation.workers.dev 2026-09-02 1
hostname mail-mofagovpk.myddns.me 2026-09-02 1
hostname forecast.com 2026-09-02 1
hostname mfagov.net 2026-09-02 1
hostname mfagov.info 2026-09-02 1
hostname passagensv.sslblindado.com 2026-09-02 3
hostname offers-ptclnetpk.serveirc.com 2026-09-02 2

Detection coverage

  • 2 YARA rules
  • 665 Sigma rules

Malware & tools used

  • Exploitation for Client Execution (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Mshta (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Process Discovery (attack-pattern)
  • JavaScript (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Web Protocols (attack-pattern)
  • Dynamic Data Exchange (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • PowerShell (attack-pattern)
  • Software Discovery (attack-pattern)
  • Visual Basic (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Automated Collection (attack-pattern)
  • Spearphishing Attachment (attack-pattern)

Exploited vulnerabilities

  • CVE-2017-11882 (vulnerability)
  • CVE-2019-2215 (vulnerability)

Related threat objects

Reports & references

  • Kaspersky — 85280 (report)
  • Trend Micro — First Active Attack Exploiting Cve 2019 2215 Found On Google Play Linked To Sidewinder Apt Group (report)
  • otx.alienvault.com — 5Fd10760F9Afb730D37C4742 (report)
  • Trend Micro — Sidewinder Leverages South Asian Territorial Issues For Spear Ph (report)
  • s.tencent.com — 659 (report)
  • Mandiant — Fireeye Sidewinder Targeted Attack (report)
  • s.tencent.com — 479 (report)
  • medium.com — Apt Sidewinder Tricks Powershell Anti Forensics And Execution Side Loading 5Bc1A7E7C84C (report)
  • mp.weixin.qq.com — 8J Rha7Gdmxy1 X8Alj8Zg (report)
  • MITRE ATT&CK — G0121 (report)
  • cdn-cybersecurity.att.com — Global Perspective Of The Sidewinder Apt (report)
  • cybleinc.com — Sidewinder Apt Targets With Futuristic Tactics And Techniques (report)

External references