logo

SideWinder targets the maritime and nuclear sectors with an updated toolset

ID: f5f1dc27-9662-5901-9224-097a94637ab7

STIX ID: report--f5f1dc27-9662-5901-9224-097a94637ab7

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2025-03-10

Date Updated: 2026-04-29

Author: Giampaolo Dedola, Vasily Berdnikov

...
...

This Kaspersky intelligence report summarizes SideWinder’s 2024 operations: a widespread spear-phishing campaign leveraging remote template injection and an RTF exploit (CVE-2017-11882) to execute mshta-delivered HTA payloads, a .NET-based Downloader Module, and a sideloaded Backdoor Loader that deploys the StealerBot in-memory implant. Targets expanded in 2024 to include maritime and logistics sectors, nuclear energy-related entities, and multiple governments and diplomatic organizations across Asia, Africa and beyond; the group rapidly iterates tools to evade detections and the report includes hashes, domains, and other IoCs plus mitigation recommendations (patching, EDR, training).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.