logo

Sidewinder Casts Wide Geographic Net in Latest Attack Spree

ID: 6ae96bbf-b968-5605-8614-24606f92f66c

STIX ID: report--6ae96bbf-b968-5605-8614-24606f92f66c

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-10-16

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

SideWinder, an India-linked APT active since 2012, has expanded operations across Asia, the Middle East, Africa and Europe using spear-phishing OOXML lures and remote template injection to exploit CVE-2017-11882; the group deploys a modular .NET implant called "StealerBot" that loads modules in memory to perform credential theft, screenshots, keylogging, file exfiltration, UAC bypass and other espionage activities, and Kaspersky publishes a comprehensive set of IoCs for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.