RST TI Report Digest: 03 Aug 2026
ID: 96913417-8fa1-582f-9626-7ad5bb6114d8
STIX ID: report--96913417-8fa1-582f-9626-7ad5bb6114d8
Feed Name: RST Cloud Blog
SideWinder APT (aka G0121 / T-APT-04) is a long-running espionage group that in 2024 broadened operations from South Asian government and military targets to critical infrastructure and diplomatic missions across 18 countries; the report documents their use of spear-phishing lures exploiting CVE-2017-11882 to deploy a memory-only implant named StealerBot (capable of stealing keystrokes, browser passwords, and RDP credentials) and provides extensive IOCs (IPs, domains, and file hashes) and observed TTPs, with no confirmed breaches of nuclear OT reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
