Beyond the Surface: the evolution and expansion of the SideWinder APT group


SideWinder, aka T-APT-04 or RattleSnake, is one of the most prolific APT groups that began its activities in 2012 and was first publicly mentioned by us in 2018. Over the years, the group has launched attacks against high-profile entities in South and Southeast Asia. Its primary targets have been military and government entities in Pakistan, Sri Lanka, China and Nepal.

Over the years, SideWinder has carried out an impressive number of attacks and its activities have been extensively described in various analyses and reports published by different researchers and vendors, one of the latest of which was released at the end of July 2024. The group may be perceived as a low-skilled actor due to the use of public exploits, malicious LNK files and scripts as infection vectors, and the use of public RATs, but their true capabilities only become apparent when you carefully examine the details of their operations.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • Cyber Signals: Inside the growing risk of gift card fraud

    May 23, 2024

    Multifactor authentication Security operations In the ever-evolving landscape of cyberthreats, staying ahead of malicious actors is a constant challenge. Microsoft Threat Intelligence has observed that gift cards are attractive targets for fraud and social engineering practices. Unlike credit or debit cards, there’s no customer name or bank account attached to them, which can lessen scrutiny of ...

  • Bank of Russia reports rising number of cyber attacks on financial infrastructure

    May 23, 2024

    The Bank of Russia reported an increase in the number of attacks on suppliers of various IT solutions used in the financial market, the regulator said in its report. “It is particularly noteworthy that attacks on third parties – suppliers of various IT solutions utilized in the financial market – have increased in frequency in 2023. ...

  • Cyber attacks on construction firms jump, new report finds

    May 23, 2024

    A new report has said that cyber attacks on construction companies doubled in the first quarter of this year compared to the same period in 2023. Risk advisory firm Kroll said the increase in attacks was “most likely due to the increased sophistication of business email compromise for either financial gain or as a pivot into ...

  • London council warns residents’ data may have been compromised by cyber attack on healthcare provider

    May 22, 2024

    A London council has warned residents their personal data may have been compromised after a healthcare provider was hit by a cyber attack. The City of London Corporation said it is working with NRS Healthcare to understand the extent of the breach, and will be in contact with any residents whose information has been taken. The ...

  • New Caledonia foils a cyberattack “of unprecedented strength”

    May 22, 2024

    Millions of emails, from “different countries”, were sent to New Caledonia on Tuesday, May 21, after the announcement of Emmanuel Macron’s visit to the territory. “An access provider suffered an attack to saturate the New Caledonian network. The teams managed to control this attack. Millions of emails were sent simultaneously to an email address, which was ...

  • Patriot Mobile Suffers Data Breach Impacting Subscriber’s Personal Data

    May 21, 2024

    U.S. mobile service provider Patriot Mobile fell victim to a security incident resulting in the leak of subscriber details including names, email addresses, zip codes, and account PINs, as reported by TechCrunch. The operator, Patriot Mobile, which boasts itself as a “Christian conservative wireless provider” with an estimated customer base under 100,000, has been seen endorsing ...