Sidewinder goes nuclear, charts course for maritime mayhem in tactics shift
ID: 39bb0cb3-36fc-5792-9a30-cbe0b54559ea
STIX ID: report--39bb0cb3-36fc-5792-9a30-cbe0b54559ea
Feed Name: The Register (Security)
Threat Score
Kaspersky reports that the Sidewinder APT has expanded in 2024 to target maritime, logistics and nuclear-sector organizations; attackers use targeted spear-phishing DOCX with remote template injection to fetch an RTF that exploits CVE-2017-11882, deploying a Backdoor Loader which installs the in-memory StealerBot implant, and the group continues to refine loaders to evade detection while maintaining a wide victimology including government and military entities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
