ATT&CKReferencesCyble Sidewinder September 2020

Cyble Sidewinder September 2020

Cyble. (2020, September 26). SideWinder APT Targets with futuristic Tactics and Techniques. Retrieved January 29, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupSidewinder

Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads.

T1105
Ingress Tool Transfer
GroupSidewinder

Sidewinder has used LNK files to download remote files to the victim's network.

T1203
Exploitation for Client Execution
GroupSidewinder

Sidewinder has exploited vulnerabilities to gain execution including CVE-2017-11882 and CVE-2020-0674.

T1204.001
Malicious Link
GroupSidewinder

Sidewinder has lured targets to click on malicious links to gain execution in the target environment.

T1204.002
Malicious File
GroupSidewinder

Sidewinder has lured targets to click on malicious files to gain execution in the target environment.

T1547.001
Registry Run Keys / Startup Folder
GroupSidewinder

Sidewinder has added paths to executables in the Registry to establish persistence.

T1566.002
Spearphishing Link
GroupSidewinder

Sidewinder has sent e-mails with malicious links often crafted for specific targets.

T1598.002
Spearphishing Attachment
GroupSidewinder

Sidewinder has sent e-mails with malicious attachments that lead victims to credential harvesting websites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.