Threat group.View on attack.mitre.org
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Sidewinder has used malware to collect information on network interfaces, including the MAC address. |
| T1020 Automated Exfiltration |
Sidewinder has configured tools to automatically send collected files to attacker controlled servers. |
| T1027.010 Command Obfuscation |
Sidewinder has used base64 encoding for scripts. |
| T1027.013 Encrypted/Encoded File |
Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads. |
| T1033 System Owner/User Discovery |
Sidewinder has used tools to identify the user of a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
Sidewinder has named malicious files |
| T1057 Process Discovery |
Sidewinder has used tools to identify running processes on the victim's machine. |
| T1059.001 PowerShell |
Sidewinder has used PowerShell to drop and execute malware loaders. |
| T1059.005 Visual Basic |
Sidewinder has used VBScript to drop and execute malware loaders. |
| T1059.007 JavaScript |
Sidewinder has used JavaScript to drop and execute malware loaders. |
| T1071.001 Web Protocols |
Sidewinder has used HTTP in C2 communications. |
| T1074.001 Local Data Staging |
Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration. |
| T1082 System Information Discovery |
Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host. |
| T1083 File and Directory Discovery |
Sidewinder has used malware to collect information on files and directories. |
| T1105 Ingress Tool Transfer |
Sidewinder has used LNK files to download remote files to the victim's network. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.