Resource Development
1 technique·derived
Thousands of domains impersonating government and webmail portals.
One of the highest-volume phishing operations in Asia, aimed at Pakistani and Chinese government targets — and increasingly at maritime shipping.
SideWinder runs one of the highest-volume spearphishing operations tracked anywhere, aimed primarily at Pakistani military and government targets, with secondary collection against Chinese, Nepalese, Sri Lankan, and Afghan entities.
Its scale is its defining feature. Researchers have documented thousands of malicious domains and hundreds of distinct phishing campaigns, with new infrastructure registered continuously. The group operates on the assumption that most of its infrastructure will be identified and burned, and simply rebuilds faster than defenders can enumerate.
The toolchain is consistent: a malicious document exploiting an old but still-effective Office vulnerability, a JavaScript or .NET loader, and a modular implant that fingerprints the host before delivering the final payload. That fingerprinting step matters — it lets the group avoid delivering its real capability to sandboxes and researchers, and is a significant reason its later-stage tooling took years to document properly.
Since 2024 the group has expanded into maritime targets — port authorities, shipping companies, and logistics operators across South and Southeast Asia and the Mediterranean — a shift consistent with growing interest in Indian Ocean shipping and regional trade routes.
Down to the named unit where public evidence supports it.
Assessed as aligned with Indian state interests based on targeting focused on Pakistan, China, and neighbouring states, infrastructure and language artifacts, and operational timing. The assessment is held with moderate confidence across the industry — attribution to India rests on targeting logic more than on hard technical or legal evidence. No government attribution or indictment exists.
Attributing sources
8 designators across 8 organisations.
1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Modular post-exploitation toolkit for credential theft, screenshots, keylogging, and file exfiltration, loaded entirely in memory.
Multi-stage loaders that fingerprint the host and refuse to deliver later stages to sandboxes and analysis environments.
Mobile malware distributed through fake applications aimed at government and military personnel.
Shared, commodity & living-off-the-land
Documents fetching weaponised remote templates only when opened by intended targets.
Thousands of registered domains impersonating government, military, and webmail portals across target countries.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by SideWinder | ||
|---|---|---|---|---|
| CVE-2023-38831KEVransomware | 7.8 | WinRARRARLAB | 1 Nov 2023 | WinRAR archive spoofing used to deliver loaders to government targets.SRCGroup-IB ↗ |
| CVE-2017-0199KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Jan 2019 | OLE2link RTF exploit used to fetch remote payloads in phishing campaigns.SRCTrend Micro ↗ |
| CVE-2017-11882KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Jan 2018 | Equation Editor overflow — the group's most persistent delivery mechanism, used across hundreds of campaigns.SRCKaspersky GReAT ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Thousands of domains impersonating government and webmail portals.
1 technique·derived
Very high volume, government and military document lures.
1 technique·derived
Exploitation for Client Execution.
3 techniques·derived
Host fingerprinting before later-stage delivery. In-memory .NET assembly loading.
2 techniques·derived
Keylogging, Data from Local System.
1 technique·derived
Web Protocols.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Thousands of domains impersonating government and webmail portals
Very high volume, government and military document lures
Host fingerprinting before later-stage delivery
In-memory .NET assembly loading
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Curated links to the reports that established what is known about this group.