Sidewinder — APT Profile
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
T-APT-04, Rattlesnake, RAZOR TIGER, APT-C-17
IntelFusions coverage (1)
- SideWinder spoofs Pakistan's port and arms agencies 2026-09-07 · Nation-State
Tools & malware
- Koadic Post-Exploitation Framework
Vendor research
- available from Rewterz Rewterz
- A Global Perspective of the SideWinder APT Hegel, T
- APT Trends report Q1 2018 Securelist
- SideWinder APT Targets with futuristic Tactics and Techniques Cyble
- A Global Perspective of the SideWinder APT ATT Sidewinder