Skip to content
IndiaState-SponsoredActiveMITRE G0121Malpedia ↗

SideWinder

One of the highest-volume phishing operations in Asia, aimed at Pakistani and Chinese government targets — and increasingly at maritime shipping.

Open MITRE Navigator layer ↗Download profile JSON
Active
2012–present
Motivation
Espionage
Aliases
8
Exploited CVEs
3
ATT&CK techniques
9
Cited sources
7

Overview

SideWinder runs one of the highest-volume spearphishing operations tracked anywhere, aimed primarily at Pakistani military and government targets, with secondary collection against Chinese, Nepalese, Sri Lankan, and Afghan entities.

Its scale is its defining feature. Researchers have documented thousands of malicious domains and hundreds of distinct phishing campaigns, with new infrastructure registered continuously. The group operates on the assumption that most of its infrastructure will be identified and burned, and simply rebuilds faster than defenders can enumerate.

The toolchain is consistent: a malicious document exploiting an old but still-effective Office vulnerability, a JavaScript or .NET loader, and a modular implant that fingerprints the host before delivering the final payload. That fingerprinting step matters — it lets the group avoid delivering its real capability to sandboxes and researchers, and is a significant reason its later-stage tooling took years to document properly.

Since 2024 the group has expanded into maritime targets — port authorities, shipping companies, and logistics operators across South and Southeast Asia and the Mediterranean — a shift consistent with growing interest in Indian Ocean shipping and regional trade routes.

Attribution

Down to the named unit where public evidence supports it.

IndiaIndian state interests (specific service not publicly designated)Moderate confidence

Assessed as aligned with Indian state interests based on targeting focused on Pakistan, China, and neighbouring states, infrastructure and language artifacts, and operational timing. The assessment is held with moderate confidence across the industry — attribution to India rests on targeting logic more than on hard technical or legal evidence. No government attribution or indictment exists.

Attributing sources

Cross-vendor naming crosswalk

8 designators across 8 organisations.

1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • SideWinder

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Storm-0343partialProvisional designator for overlapping activity

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Razor Tiger

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Secureworks CTU

index ↗
  • TIN BAROMETER

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Recorded Future Insikt Group

index ↗
  • APT-C-17Qihoo 360 designator widely cross-referenced

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Kaspersky GReAT

index ↗
  • SideWinder

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Trend Micro

index ↗
  • Rattlesnake

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

CISA / NSA / FBI

index ↗
  • SideWinder

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

PakistanChinaNepalSri LankaAfghanistanBangladeshMaldivesEgyptDjibouti

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

StealerBotmalware

Modular post-exploitation toolkit for credential theft, screenshots, keylogging, and file exfiltration, loaded entirely in memory.

SideWinder .NET loadersloader

Multi-stage loaders that fingerprint the host and refuse to deliver later stages to sandboxes and analysis environments.

Android implantsmalware

Mobile malware distributed through fake applications aimed at government and military personnel.

Shared, commodity & living-off-the-land

Remote template injectionutility

Documents fetching weaponised remote templates only when opened by intended targets.

Mass domain infrastructureutility

Thousands of registered domains impersonating government, military, and webmail portals across target countries.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by SideWinder
CVE-2023-38831KEVransomware7.81 Nov 2023WinRAR archive spoofing used to deliver loaders to government targets.SRCGroup-IB
CVE-2017-0199KEVransomware7.81 Jan 2019OLE2link RTF exploit used to fetch remote payloads in phishing campaigns.SRCTrend Micro
CVE-2017-11882KEVransomware7.81 Jan 2018Equation Editor overflow — the group's most persistent delivery mechanism, used across hundreds of campaigns.SRCKaspersky GReAT

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

6 stages · 9 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
9 techniques across 6 tactics · 4 with actor-specific notes

Resource Development

1

Initial Access

1

Defense Evasion

3

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.