Sidewinder
MITRE ATT&CK: G0121 View on attack.mitre.org
Aliases: T-APT-04, Rattlesnake, SideWinder, APT-C-17, Sidewinder
- First seen
- 2012-01-01 00:00:00
- Origin
- IN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 390 (225 malicious)
- Last IoC activity
- 2026-09-02 00:38:45
- Profile updated
- 2026-07-07 11:58:49
Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:pk country_code:cn country_code:np country_code:af
Context
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.
Recent IoC activity
225 malicious indicators in Maltiverse are attributed to Sidewinder (G0121). The 20 most recently updated:
Detection coverage
- 2 YARA rules
- 665 Sigma rules
Malware & tools used
- Exploitation for Client Execution (attack-pattern)
- Security Software Discovery (attack-pattern)
- Mshta (attack-pattern)
- Spearphishing Link (attack-pattern)
- System Time Discovery (attack-pattern)
- Spearphishing Link (attack-pattern)
- Local Data Staging (attack-pattern)
- Process Discovery (attack-pattern)
- JavaScript (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Automated Exfiltration (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Web Protocols (attack-pattern)
- Dynamic Data Exchange (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Command Obfuscation (attack-pattern)
- PowerShell (attack-pattern)
- Software Discovery (attack-pattern)
- Visual Basic (attack-pattern)
- System Information Discovery (attack-pattern)
- Automated Collection (attack-pattern)
- Spearphishing Attachment (attack-pattern)
Exploited vulnerabilities
- CVE-2017-11882 (vulnerability)
- CVE-2019-2215 (vulnerability)
Related threat objects
- SideWinder (Windows) (malware)
Reports & references
- Kaspersky — 85280 (report)
- Trend Micro — First Active Attack Exploiting Cve 2019 2215 Found On Google Play Linked To Sidewinder Apt Group (report)
- otx.alienvault.com — 5Fd10760F9Afb730D37C4742 (report)
- Trend Micro — Sidewinder Leverages South Asian Territorial Issues For Spear Ph (report)
- s.tencent.com — 659 (report)
- Mandiant — Fireeye Sidewinder Targeted Attack (report)
- s.tencent.com — 479 (report)
- medium.com — Apt Sidewinder Tricks Powershell Anti Forensics And Execution Side Loading 5Bc1A7E7C84C (report)
- mp.weixin.qq.com — 8J Rha7Gdmxy1 X8Alj8Zg (report)
- MITRE ATT&CK — G0121 (report)
- cdn-cybersecurity.att.com — Global Perspective Of The Sidewinder Apt (report)
- cybleinc.com — Sidewinder Apt Targets With Futuristic Tactics And Techniques (report)