Beyond the Surface: the evolution and expansion of the SideWinder APT group


SideWinder, aka T-APT-04 or RattleSnake, is one of the most prolific APT groups that began its activities in 2012 and was first publicly mentioned by us in 2018. Over the years, the group has launched attacks against high-profile entities in South and Southeast Asia. Its primary targets have been military and government entities in Pakistan, Sri Lanka, China and Nepal.

Over the years, SideWinder has carried out an impressive number of attacks and its activities have been extensively described in various analyses and reports published by different researchers and vendors, one of the latest of which was released at the end of July 2024. The group may be perceived as a low-skilled actor due to the use of public exploits, malicious LNK files and scripts as infection vectors, and the use of public RATs, but their true capabilities only become apparent when you carefully examine the details of their operations.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • New Marsilia Ransomware Downloader Found

    March 4, 2024

    This week, the SonicWall Capture Labs threat research team analyzed a sample of Marsilia malware, also known as Mallox. This is a multi-stage sample that, when functional, will have a first stage that enumerates system information and creates persistence. The second stage is then downloaded and will perform data extraction and encryption for ransomware purposes. The ...

  • New Banking Trojan “CHAVECLOAK” Targets Brazil

    March 4, 2024

    FortiGuard Labs recently uncovered a threat actor employing a malicious PDF file to propagate the banking Trojan CHAVECLOAK. This intricate attack involves the PDF downloading a ZIP file and subsequently utilizing DLL side-loading techniques to execute the final malware. Notably, CHAVECLOAK is specifically designed to target users in Brazil, aiming to steal sensitive information linked to ...

  • Three underwater data cables providing Internet through Red Sea are cut amid Al Houthi militant attacks

    March 4, 2024

    An incident in the Red Sea has cut three underwater sea cables providing internet and telecommunications around the world as the waterway remains a target of Yemen’s Houthi militants, officials said on Monday. A statement by Hong Kong-based HGC Global Communications acknowledged the cuts but did not say what caused the lines to be severed. Read more… Source: ...

  • South Africa: CIPC cyber attack leaves millions of entities vulnerable across nation

    March 4, 2024

    Sensitive data of at least three-million entities and individuals who were registered with the Companies and Intellectual Property Commission (CIPC) could have fallen into the wrong hands when the organisation’s database was hacked this week. Addresses, credit card details, ID numbers and names of companies and individuals might be compromised and the CIPC has called on ...

  • BiBi attacks Israel: Pro-Hamas hackers use new malware to attack Israeli companies

    March 3, 2024

    A wave of new cyberattacks from pro-Hamas hackers using the BiBi malware has been identified in Israel in recent days. This involves four new variants of malware that are able to evade antivirus engines, according to the VirusTotal platform. The BiBi malware is a wiper-type malware designed to erase and corrupt data. Unlike other types of ...

  • North Carolina: Around £2.1 million has been stolen from the housing agency as the US Secret Service is investigating

    March 3, 2024

    It is a little-known clothing firm based out of an anonymous residential street in Scotland’s biggest city, with overflowing bags and boxes of rubbish piled up outside its front door. But a Glasgow company is at the centre of a multi-million pound fraud investigation by the US Secret Service into millions of public money that was ...