WHOIS API
Analysis of SideWinder Advanced Persistent Threat Activities
Pages
8
Time to read
6 mins
Language
English
Pages
8
Time to read
6 mins
Language
English
This technical report details the activities of the SideWinder advanced persistent threat (APT) group, which has been operational since 2012 and primarily targets government, military, and business entities in Asia, including Pakistan, China, Nepal, and Afghanistan. The report outlines the group's recent updates to their toolset and infrastructure, which have led to increased attacks on maritime and logistics companies in Djibouti and Egypt, as well as on nuclear power plants in South Asia and Africa. A total of 35 domains were identified as indicators of compromise (IoCs) related to the latest SideWinder attack. The report presents findings from various queries conducted on these IoCs, revealing details such as domain registration information, historical domain-to-IP address resolutions, and the identification of malicious domains associated with the SideWinder group. The analysis concludes with a summary of 579 potentially connected artifacts, including email-connected domains, IP addresses, and string-connected domains, highlighting the ongoing threat posed by this APT group.