ATT&CKGroupsSidewinder

Sidewinder

G0121

Threat group.View on attack.mitre.org

About this group

Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.

Techniques used30

Procedure examples30

TechniqueProcedure example
T1016
System Network Configuration Discovery

Sidewinder has used malware to collect information on network interfaces, including the MAC address.

T1020
Automated Exfiltration

Sidewinder has configured tools to automatically send collected files to attacker controlled servers.

T1027.010
Command Obfuscation

Sidewinder has used base64 encoding for scripts.

T1027.013
Encrypted/Encoded File

Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads.

T1033
System Owner/User Discovery

Sidewinder has used tools to identify the user of a compromised host.

T1036.005
Match Legitimate Resource Name or Location

Sidewinder has named malicious files rekeywiz.exe to match the name of a legitimate Windows executable.

T1057
Process Discovery

Sidewinder has used tools to identify running processes on the victim's machine.

T1059.001
PowerShell

Sidewinder has used PowerShell to drop and execute malware loaders.

T1059.005
Visual Basic

Sidewinder has used VBScript to drop and execute malware loaders.

T1059.007
JavaScript

Sidewinder has used JavaScript to drop and execute malware loaders.

T1071.001
Web Protocols

Sidewinder has used HTTP in C2 communications.

T1074.001
Local Data Staging

Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration.

T1082
System Information Discovery

Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host.

T1083
File and Directory Discovery

Sidewinder has used malware to collect information on files and directories.

T1105
Ingress Tool Transfer

Sidewinder has used LNK files to download remote files to the victim's network.

View all 30 procedure examples

Software1

Campaigns0

None recorded.

References3

  1. ATT Sidewinder January 2021 Open source
    Hegel, T. (2021, January 13). A Global Perspective of the SideWinder APT. Retrieved January 27, 2021.
  2. Cyble Sidewinder September 2020 Open source
    Cyble. (2020, September 26). SideWinder APT Targets with futuristic Tactics and Techniques. Retrieved January 29, 2021.
  3. Securelist APT Trends April 2018 Open source
    Global Research and Analysis Team . (2018, April 12). APT Trends report Q1 2018. Retrieved January 27, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.