Sidewinder Casts Wide Geographic Net in Latest Attack Spree
ID: 6ae96bbf-b968-5605-8614-24606f92f66c
STIX ID: report--6ae96bbf-b968-5605-8614-24606f92f66c
Feed Name: Dark Reading
Date Published: 2024-10-16
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
SideWinder, an India-linked APT active since 2012, has expanded operations across Asia, the Middle East, Africa and Europe using spear-phishing OOXML lures and remote template injection to exploit CVE-2017-11882; the group deploys a modular .NET implant called "StealerBot" that loads modules in memory to perform credential theft, screenshots, keylogging, file exfiltration, UAC bypass and other espionage activities, and Kaspersky publishes a comprehensive set of IoCs for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
